MEDIUM
Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04
Published Jan 18, 2006
5.0
MEDIUMCVSS 2.0
EPSS 5.01%
Description
Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04. NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.
Affected products
No data.
- 9.0.4.2
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (11)
- http://secunia.com/advisories/18493 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/18608 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1015499 vdb-entryx_refsource_SECTRACK
- http://www.kb.cert.org/vuls/id/545804 third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource
- http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html x_refsource_CONFIRM
- http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html x_refsource_MISC
- http://www.securityfocus.com/archive/1/422261/30/7430/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/16287 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/0243 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/0323 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/18493 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://secunia.com/advisories/18608 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://securitytracker.com/id?1015499 | vdb-entryx_refsource_SECTRACK | |
| http://www.kb.cert.org/vuls/id/545804 | third-party-advisoryx_refsource_CERT-VNThird Party AdvisoryUS Government Resource | |
| http://www.oracle.com/technetwork/topics/security/cpujan2006-082403.html | x_refsource_CONFIRM | |
| http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html | x_refsource_MISC | |
| http://www.securityfocus.com/archive/1/422261/30/7430/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/16287 | vdb-entryx_refsource_BID | |
| http://www.vupen.com/english/advisories/2006/0243 | vdb-entryx_refsource_VUPENVendor Advisory | |
| http://www.vupen.com/english/advisories/2006/0323 | vdb-entryx_refsource_VUPENVendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/24321 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 18, 2006
Updated Aug 7, 2024
Reserved Jan 18, 2006
Link CVE-2006-0275
CISA Vulnrichment
Updated n/a