Oracle JD Edwards EnterpriseOne Tools CVE-2011-2317 Arbitrary File Upload Vulnerability
BID:51456
Info
Oracle JD Edwards EnterpriseOne Tools CVE-2011-2317 Arbitrary File Upload Vulnerability
| Bugtraq ID: | 51456 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-2317 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2012 12:00AM |
| Updated: | Mar 19 2015 08:45AM |
| Credit: | Oracle |
| Vulnerable: |
Oracle JD Edwards EnterpriseOne Server 9.0 Oracle JD Edwards EnterpriseOne 8.95 _F1 Oracle JD Edwards EnterpriseOne 8.95 _B1 Oracle JD Edwards EnterpriseOne 8.94 _Q1 Oracle JD Edwards EnterpriseOne 8.98.4.1 Oracle JD Edwards EnterpriseOne 8.98 Oracle JD Edwards EnterpriseOne 8.97 Oracle JD Edwards EnterpriseOne 8.96 Oracle JD Edwards EnterpriseOne 8.95.J1 Oracle JD Edwards EnterpriseOne 8.95 |
| Not Vulnerable: | |
Discussion
Oracle JD Edwards EnterpriseOne Tools CVE-2011-2317 Arbitrary File Upload Vulnerability
Oracle JD Edwards EnterpriseOne Tools is prone to a Arbitrary File Upload vulnerability
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastucture SEC (JDNET)' sub component is affected.
Exploiting this issue can allow an attacker to upload arbitrary code and run it in the context of the webserver process.
Oracle JD Edwards EnterpriseOne Tools is prone to a Arbitrary File Upload vulnerability
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastucture SEC (JDNET)' sub component is affected.
Exploiting this issue can allow an attacker to upload arbitrary code and run it in the context of the webserver process.
Exploit / POC
Oracle JD Edwards EnterpriseOne Tools CVE-2011-2317 Arbitrary File Upload Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle JD Edwards EnterpriseOne Tools CVE-2011-2317 Arbitrary File Upload Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle JD Edwards EnterpriseOne Tools CVE-2011-2317 Arbitrary File Upload Vulnerability
References:
References: