Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04. NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.
References
Configurations
History
21 Nov 2024, 00:06
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/18493 - Vendor Advisory | |
References | () http://secunia.com/advisories/18608 - Vendor Advisory | |
References | () http://securitytracker.com/id?1015499 - | |
References | () http://www.kb.cert.org/vuls/id/545804 - Third Party Advisory, US Government Resource | |
References | () http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html - | |
References | () http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html - | |
References | () http://www.securityfocus.com/archive/1/422261/30/7430/threaded - | |
References | () http://www.securityfocus.com/bid/16287 - | |
References | () http://www.vupen.com/english/advisories/2006/0243 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2006/0323 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 - |
Information
Published : 2006-01-18 11:03
Updated : 2024-11-21 00:06
NVD link : CVE-2006-0275
Mitre link : CVE-2006-0275
CVE.ORG link : CVE-2006-0275
JSON object : View
Products Affected
oracle
- application_server
CWE