Oracle JDEdwards EnterpriseOne Tools CVE-2011-3524 Information Disclosure Vulnerability
BID:51468
Info
Oracle JDEdwards EnterpriseOne Tools CVE-2011-3524 Information Disclosure Vulnerability
| Bugtraq ID: | 51468 |
| Class: | Design Error |
| CVE: |
CVE-2011-3524 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2012 12:00AM |
| Updated: | Mar 19 2015 09:29AM |
| Credit: | Oracle |
| Vulnerable: |
Oracle JDEdwards 8.98 Oracle JD Edwards EnterpriseOne Server 9.0 Oracle JD Edwards EnterpriseOne 8.95 _F1 Oracle JD Edwards EnterpriseOne 8.95 _B1 Oracle JD Edwards EnterpriseOne 8.94 _Q1 Oracle JD Edwards EnterpriseOne 8.98 Oracle JD Edwards EnterpriseOne 8.97 Oracle JD Edwards EnterpriseOne 8.96 Oracle JD Edwards EnterpriseOne 8.95.J1 Oracle JD Edwards EnterpriseOne 8.95 |
| Not Vulnerable: | |
Discussion
Oracle JDEdwards EnterpriseOne Tools CVE-2011-3524 Information Disclosure Vulnerability
Oracle JDEdwards EnterpriseOne Tools is prone to a remote information-disclosure vulnerability.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
An attacker can exploit this issue to obtain sensitive information from the 'JDE.INI' configuration file.
Oracle JDEdwards EnterpriseOne Tools is prone to a remote information-disclosure vulnerability.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
An attacker can exploit this issue to obtain sensitive information from the 'JDE.INI' configuration file.
Exploit / POC
Oracle JDEdwards EnterpriseOne Tools CVE-2011-3524 Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle JDEdwards EnterpriseOne Tools CVE-2011-3524 Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle JDEdwards EnterpriseOne Tools CVE-2011-3524 Information Disclosure Vulnerability
References:
References: