Overview
A vulnerability in Oracle's E-Business Suite Report Review Agent (RRA) allows arbitrary files to be retrieved with no authentication.
Description
A vulnerability exists in the Oracle E-Business Suite Report Review Agent (RRA). This vulnerability may allow a remote attacker to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. For more information, please see the following documents: |
Impact
A remote attacker may be able to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. |
Solution
Apply a vendor supplied patch. |
Mitigation |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was discovered by Stephen Kost of Integrigy Corporation.
This document was written by Ian A Finlay.
Other Information
CVE IDs: | None |
Severity Metric: | 9.38 |
Date Public: | 2003-04-10 |
Date First Published: | 2003-04-14 |
Date Last Updated: | 2003-04-14 16:54 UTC |
Document Revision: | 15 |