Oracle JDEdwards CVE-2011-2325 Password Disclosure Security Vulnerability
BID:51486
Info
Oracle JDEdwards CVE-2011-2325 Password Disclosure Security Vulnerability
| Bugtraq ID: | 51486 |
| Class: | Unknown |
| CVE: |
CVE-2011-2325 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 17 2012 12:00AM |
| Updated: | Feb 24 2012 01:30PM |
| Credit: | Oracle |
| Vulnerable: |
Oracle JDEdwards 8.98 |
| Not Vulnerable: | |
Discussion
Oracle JDEdwards CVE-2011-2325 Password Disclosure Security Vulnerability
Oracle JDEdwards is prone to a remote information-disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
Successful exploitation will allow an attacker to disclose sensitive information that may aid in further attacks.
This vulnerability affects the following supported versions:
8.98
Oracle JDEdwards is prone to a remote information-disclosure vulnerability in JD Edwards EnterpriseOne Tools.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
Successful exploitation will allow an attacker to disclose sensitive information that may aid in further attacks.
This vulnerability affects the following supported versions:
8.98
Exploit / POC
Oracle JDEdwards CVE-2011-2325 Password Disclosure Security Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Oracle JDEdwards CVE-2011-2325 Password Disclosure Security Vulnerability
Solution:
Vendor updates are available. Please contact the vendor for more information.
Solution:
Vendor updates are available. Please contact the vendor for more information.
References
Oracle JDEdwards CVE-2011-2325 Password Disclosure Security Vulnerability
References:
References:
- [Onapsis Security Advisory 2012-02] Oracle JD Edwards Security Kernel Remote Pas (Onapsis Research Labs)
- Oracle Critical Patch Update Advisory - January 2012 (Oracle)