Oracle Reports Server DESName Remote File Overwrite Vulnerability
BID:14309
Info
Oracle Reports Server DESName Remote File Overwrite Vulnerability
| Bugtraq ID: | 14309 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-2371 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2005 12:00AM |
| Updated: | Jul 19 2005 12:00AM |
| Credit: | Alexander Kornbrust <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Oracle Oracle Reports6i 6.0.8 .19 Oracle Oracle Reports6i 6.0.8 Oracle Oracle Reports 9i Oracle Oracle Reports 6 Oracle Oracle Reports 10g 9.0.4 .3.3 Oracle Oracle Reports 10g 9.0.4 Oracle Oracle Reports 10g 9.0.3 Oracle Oracle Reports 10g 9.0.2 Oracle Oracle Reports 10g 9.0.1 Oracle Oracle Reports 10g 9.0 |
| Not Vulnerable: | |
Discussion
Oracle Reports Server DESName Remote File Overwrite Vulnerability
Oracle Reports Server is susceptible to an arbitrary file overwrite vulnerability in its Web interface.
On the Microsoft Windows platform, attackers may exploit this vulnerability to overwrite arbitrary files with System-level privileges. Attackers may overwrite critical system files, resulting in a system-level failures.
On other platforms, attackers may exploit this vulnerability to overwrite arbitrary files with the privileges of the Oracle Applications Server user. Attackers may overwrite critical Oracle files, resulting in an application-level failure.
Database failure, data destruction, and possibly other attacks are possible.
Oracle Reports Server is susceptible to an arbitrary file overwrite vulnerability in its Web interface.
On the Microsoft Windows platform, attackers may exploit this vulnerability to overwrite arbitrary files with System-level privileges. Attackers may overwrite critical system files, resulting in a system-level failures.
On other platforms, attackers may exploit this vulnerability to overwrite arbitrary files with the privileges of the Oracle Applications Server user. Attackers may overwrite critical Oracle files, resulting in an application-level failure.
Database failure, data destruction, and possibly other attacks are possible.
Exploit / POC
Oracle Reports Server DESName Remote File Overwrite Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Oracle Reports Server DESName Remote File Overwrite Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Oracle Reports Server DESName Remote File Overwrite Vulnerability
References:
References:
- Oracle File Overwrite Security Vulnerability (Oracle)
- Oracle Homepage (Oracle)
- Overwrite any file via desname in Oracle Reports (Red-Database-Security GmbH)
- Oracle Security Advisory: Overwrite any file via desname in Oracle Reports ([email protected])