Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Oracle Configurator System Information Leak Vulnerability

An issue has been discovered in Oracle Configurator, which could allow a remote user to gain knowledge of sensitive system information.

This issue is achievable when submitting certain requests to the 'oracle.apps.cz.servlet.UiServlet' servlet. The host can be led to reveal the version, hostname and port information.

This information can be used to assist in further attacks against the host.







 

Privacy Statement
Copyright 2009, SecurityFocus