Описание
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
Ссылки
- Vendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- ExploitVendor Advisory
- ExploitVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:oracle:reports:*:*:*:*:*:*:*:*
EPSS
Процентиль: 87%
0.03517
Низкий
5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
почти 4 года назад
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
EPSS
Процентиль: 87%
0.03517
Низкий
5 Medium
CVSS2
Дефекты
CWE-22