Oracle Fusion Middleware CVE-2010-3581 BPEL Console Cross Site Scripting Vulnerability
BID:43954
Info
Oracle Fusion Middleware CVE-2010-3581 BPEL Console Cross Site Scripting Vulnerability
| Bugtraq ID: | 43954 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3581 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2010 12:00AM |
| Updated: | Oct 27 2010 06:08PM |
| Credit: | Alexander Polyakov from Digital Security |
| Vulnerable: |
Oracle Fusion Middleware 10.1.3 .5 Oracle Fusion Middleware 10.1.2 .3 |
| Not Vulnerable: | |
Discussion
Oracle Fusion Middleware CVE-2010-3581 BPEL Console Cross Site Scripting Vulnerability
Oracle Fusion Middleware is prone to a cross-site scripting vulnerability in BPEL Console.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'Valid Session' privileges.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Oracle BPEL Console 10.1.3.3.0 is vulnerable.
Oracle Fusion Middleware is prone to a cross-site scripting vulnerability in BPEL Console.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'Valid Session' privileges.
An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may let the attacker steal cookie-based authentication credentials and launch other attacks.
Oracle BPEL Console 10.1.3.3.0 is vulnerable.
Exploit / POC
Oracle Fusion Middleware CVE-2010-3581 BPEL Console Cross Site Scripting Vulnerability
To exploit this issue, attackers must entice an unsuspecting user into visiting a specially crafted URI.
The following example URI is available:
To exploit this issue, attackers must entice an unsuspecting user into visiting a specially crafted URI.
The following example URI is available:
Solution / Fix
Oracle Fusion Middleware CVE-2010-3581 BPEL Console Cross Site Scripting Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle Fusion Middleware CVE-2010-3581 BPEL Console Cross Site Scripting Vulnerability
References:
References:
- [DSECRG-09-032] Oracle Application Server - Linked XSS vulnerability (Digital Security Research Group)
- [DSECRG-09-032] Oracle Application Server - Linked XSS vulnerability (DSecRG
) - Oracle Critical Patch Update Advisory - October 2010 (Oracle)