Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
|
|
|
|
|
|
|
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
|
|
|
|
Become a Partner and License Our Database or Notification Service
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Oracle E-Business Suite Bugs Let Remote Authenticated Users Access and Modify Data and Cause Denial of Service Conditions
|
|
SecurityTracker Alert ID: 1020495
|
|
SecurityTracker URL: http://securitytracker.com/id?1020495
|
|
CVE Reference: CVE-2008-2585
, CVE-2008-2586
, CVE-2008-2596
, CVE-2008-2601
, CVE-2008-2606
, CVE-2008-2610
(Links to External Site)
|
Date: Jul 15 2008
|
Impact: Denial of service via network, Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Oracle Security Advisory
|
Version(s): 12.0.4 and prior versions
|
Description: Several vulnerabilities were reported in Oracle E-Business Suite. A remote authenticated user can access and modify data on the target system. A remote authenticated user can cause denial of service conditions.
A remote authenticated user can exploit several unspecified vulnerabilities to affect the confidentiality and integrity of data on
the target system.
A remote authenticated user can cause unspecified "partial" denial of service conditions.
No details were
provided.
The Mobile Application Server [CVE-2008-2596], Oracle Report Manager [CVE-2008-2585], Oracle iStore [CVE-2008-2601],
Oracle Application Object Library [CVE-2008-2586], Oracle Application Object Library [CVE-2008-2606], and Oracle Applications Technology
Stack [CVE-2008-2610] components are affected.
The following versions are affected:
- Oracle E-Business Suite Release 12,
version 12.0.4
- Oracle E-Business Suite Release 11i, version 11.5.10.2
The following researchers reported these and other Oracle
vulnerabilities:
Flavio Casetta of Yocoya; Esteban Martinez Fayo of Application Security, Inc.; Johannes Greil of SEC Consult;
guyp of Sentrigo; Joxean Koret; Alexander Kornbrust of Red Database Security; Stephen Kost of Integrigy; Dave Lewis; David Litchfield
of NGS Software; Hirofumi Oka of JPCERT/CC Vulnerability Handling Team; Tanel Poder; Alexandr Polyakov of Digital Security; Andrea
Purificato; and Dave Wichers of Aspect Security.
|
Impact: A remote authenticated user can access and modify data on the target system.
A remote authenticated user can cause denial of service conditions on the target system.
|
Solution: The vendor has issued a fix, described in their July 2008 Critical Patch Update advisory.
The Oracle advisory is available at:
http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html
|
Vendor URL: www.oracle.com/technology/deploy/security/critical-patch-updates/cpujul2008.html (Links to External Site)
|
Cause: Not specified
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), UNIX (Tru64), Windows (NT), Windows (2000), Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|
Go to the Top of This SecurityTracker Archive Page
|