Oracle JDEdwards CVE-2011-2326 Information Disclosure Vulnerability
BID:51482
Info
Oracle JDEdwards CVE-2011-2326 Information Disclosure Vulnerability
| Bugtraq ID: | 51482 |
| Class: | Unknown |
| CVE: |
CVE-2011-2326 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2012 12:00AM |
| Updated: | Feb 24 2012 11:13AM |
| Credit: | Oracle |
| Vulnerable: |
Oracle JDEdwards 8.98 |
| Not Vulnerable: | |
Discussion
Oracle JDEdwards CVE-2011-2326 Information Disclosure Vulnerability
Oracle JDEdwards is prone to an information-disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
Attackers can exploit this issue to obtain sensitive information such as the USER, ROLE, ENVIRONMENT tuples that may lead to further attacks.
This vulnerability affects the following supported versions:
8.98
Oracle JDEdwards is prone to an information-disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
Attackers can exploit this issue to obtain sensitive information such as the USER, ROLE, ENVIRONMENT tuples that may lead to further attacks.
This vulnerability affects the following supported versions:
8.98
Exploit / POC
Oracle JDEdwards CVE-2011-2326 Information Disclosure Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle JDEdwards CVE-2011-2326 Information Disclosure Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle JDEdwards CVE-2011-2326 Information Disclosure Vulnerability
References:
References: