{"api_version":"1","generated_at":"2026-07-23T04:32:54+00:00","cve":"CVE-2003-1116","urls":{"html":"https://cve.report/CVE-2003-1116","api":"https://cve.report/api/cve/CVE-2003-1116.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-1116","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-1116"},"summary":{"title":"CVE-2003-1116","description":"The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11768","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11768","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/7325","name":"http://www.securityfocus.com/bid/7325","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Oracle E-Business Suite RRA/FNDFS Arbitrary File Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/168873","name":"http://www.kb.cert.org/vuls/id/168873","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource"],"title":"CERT/CC Vulnerability Note VU#168873","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm","name":"http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Search | Integrigy","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=105012832418415&w=2","name":"http://marc.info/?l=bugtraq&m=105012832418415&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1006550","name":"http://securitytracker.com/id?1006550","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Oracle E-Business Suite Report Review Agent Discloses Files to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf","name":"http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Technical Resources | Oracle","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-1116","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-1116","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"10.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"1116","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"e-business_suite","cpe6":"11.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:12:36.022Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20030411 Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=105012832418415&w=2"},{"name":"7325","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/7325"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf"},{"name":"oracle-rra-authentication-bypass(11768)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11768"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm"},{"name":"VU#168873","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/168873"},{"name":"1006550","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1006550"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-04-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20030411 Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=105012832418415&w=2"},{"name":"7325","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/7325"},{"tags":["x_refsource_CONFIRM"],"url":"http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf"},{"name":"oracle-rra-authentication-bypass(11768)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11768"},{"tags":["x_refsource_MISC"],"url":"http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm"},{"name":"VU#168873","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/168873"},{"name":"1006550","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1006550"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-1116","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20030411 Integrigy Security Advisory - Oracle Applications FNDFS Vulnerability","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=105012832418415&w=2"},{"name":"7325","refsource":"BID","url":"http://www.securityfocus.com/bid/7325"},{"name":"http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf","refsource":"CONFIRM","url":"http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf"},{"name":"oracle-rra-authentication-bypass(11768)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/11768"},{"name":"http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm","refsource":"MISC","url":"http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm"},{"name":"VU#168873","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/168873"},{"name":"1006550","refsource":"SECTRACK","url":"http://securitytracker.com/id?1006550"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-1116","datePublished":"2005-03-12T05:00:00.000Z","dateReserved":"2005-03-11T00:00:00.000Z","dateUpdated":"2024-08-08T02:12:36.022Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:10.7:*:*:*:*:*:*:*","matchCriteriaId":"A697B2D5-1F33-47D8-A490-F0DEDD802549"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.0:*:*:*:*:*:*:*","matchCriteriaId":"120ED075-8649-44F1-A79C-99C040C2E365"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.1:*:*:*:*:*:*:*","matchCriteriaId":"34112DA5-C0B6-46E9-A69F-02F24BDBA6ED"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.2:*:*:*:*:*:*:*","matchCriteriaId":"F6883CFF-B2CB-4B75-8E6B-938A78CF7DFA"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.3:*:*:*:*:*:*:*","matchCriteriaId":"9134636B-0CF6-41BE-8C5F-BB6C0C55A199"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.4:*:*:*:*:*:*:*","matchCriteriaId":"5B512964-2367-4C55-BB75-9EBFB3707179"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.5:*:*:*:*:*:*:*","matchCriteriaId":"1DC2C3EF-B1A4-4BF9-B534-A7ABB6490CCF"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.6:*:*:*:*:*:*:*","matchCriteriaId":"BC900808-1118-4FC0-9E48-380A02394F45"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.7:*:*:*:*:*:*:*","matchCriteriaId":"CD00F5CD-125C-4895-824E-23AC1D9A34BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:e-business_suite:11.8:*:*:*:*:*:*:*","matchCriteriaId":"9FE95D02-C2A8-4AAC-878B-DFA0FE13B571"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"1116","Ordinal":"1","Title":"CVE-2003-1116","CVE":"CVE-2003-1116","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"1116","Ordinal":"1","NoteData":"The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.","Type":"Description","Title":"CVE-2003-1116"},{"CveYear":"2003","CveId":"1116","Ordinal":"2","NoteData":"2005-03-12","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"1116","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}