Oracle JD Edwards EnterpriseOne Multiple Cross Site Scripting Vulnerabilities
BID:47479
Info
Oracle JD Edwards EnterpriseOne Multiple Cross Site Scripting Vulnerabilities
| Bugtraq ID: | 47479 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0836 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2011 12:00AM |
| Updated: | Mar 19 2015 08:44AM |
| Credit: | Juan Manuel Garcia |
| Vulnerable: |
Oracle JD Edwards OneWorld Tools 24.1.3 Oracle JD Edwards OneWorld Tools 24.1 Oracle JD Edwards EnterpriseOne 8.95 _F1 Oracle JD Edwards EnterpriseOne 8.95 _B1 Oracle JD Edwards EnterpriseOne 8.94 _Q1 Oracle JD Edwards EnterpriseOne 8.98.4.1 Oracle JD Edwards EnterpriseOne 8.98 Oracle JD Edwards EnterpriseOne 8.97 Oracle JD Edwards EnterpriseOne 8.96 Oracle JD Edwards EnterpriseOne 8.95.J1 Oracle JD Edwards EnterpriseOne 8.95 |
| Not Vulnerable: | |
Discussion
Oracle JD Edwards EnterpriseOne Multiple Cross Site Scripting Vulnerabilities
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
Exploit / POC
Oracle JD Edwards EnterpriseOne Multiple Cross Site Scripting Vulnerabilities
Attackers can use a browser to exploit this issue.
The following example URIs are available:
Attackers can use a browser to exploit this issue.
The following example URIs are available:
Solution / Fix
Oracle JD Edwards EnterpriseOne Multiple Cross Site Scripting Vulnerabilities
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle JD Edwards EnterpriseOne Multiple Cross Site Scripting Vulnerabilities
References:
References: