Oracle JDEdwards CVE-2011-3509 Remote File Disclosure Vulnerability
BID:51459
Info
Oracle JDEdwards CVE-2011-3509 Remote File Disclosure Vulnerability
| Bugtraq ID: | 51459 |
| Class: | Unknown |
| CVE: |
CVE-2011-3509 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2012 12:00AM |
| Updated: | Feb 24 2012 07:40AM |
| Credit: | Oracle |
| Vulnerable: |
Oracle JDEdwards 8.98 |
| Not Vulnerable: | |
Discussion
Oracle JDEdwards CVE-2011-3509 Remote File Disclosure Vulnerability
Oracle JDEdwards is prone to a remote file disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
An attacker can exploit this issue to view arbitrary files in the context of the affected application. This may aid in further attacks.
This vulnerability affects the following supported versions:
8.98
Oracle JDEdwards is prone to a remote file disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
An attacker can exploit this issue to view arbitrary files in the context of the affected application. This may aid in further attacks.
This vulnerability affects the following supported versions:
8.98
Exploit / POC
Oracle JDEdwards CVE-2011-3509 Remote File Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle JDEdwards CVE-2011-3509 Remote File Disclosure Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle JDEdwards CVE-2011-3509 Remote File Disclosure Vulnerability
References:
References: