Oracle E-Business Suite Oracle iRecruitment HTML Injection Vulnerability
BID:43969
Info
Oracle E-Business Suite Oracle iRecruitment HTML Injection Vulnerability
| Bugtraq ID: | 43969 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2404 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2010 12:00AM |
| Updated: | Jul 15 2011 04:40PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle E-Business Suite 12 12.1.2 Oracle E-Business Suite 12 12.0.6 Oracle E-Business Suite 11i 11.5.10.2 |
| Not Vulnerable: | |
Discussion
Oracle E-Business Suite Oracle iRecruitment HTML Injection Vulnerability
Oracle E-Business Suite is prone to an HTML-injection vulnerability in Oracle iRecruitment.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'Account' privileges.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
This vulnerability affects the following supported versions:
11.5.10.2, 12.0.6, 12.1.2
Oracle E-Business Suite is prone to an HTML-injection vulnerability in Oracle iRecruitment.
The vulnerability can be exploited over the 'HTTP' protocol. For an exploit to succeed, the attacker must have 'Account' privileges.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials or to control how the site is rendered to the user. Other attacks are also possible.
This vulnerability affects the following supported versions:
11.5.10.2, 12.0.6, 12.1.2
Exploit / POC
Oracle E-Business Suite Oracle iRecruitment HTML Injection Vulnerability
Attackers can exploit this issue with a web browser.
Attackers can exploit this issue with a web browser.
Solution / Fix
Oracle E-Business Suite Oracle iRecruitment HTML Injection Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle E-Business Suite Oracle iRecruitment HTML Injection Vulnerability
References:
References: