Overview
A vulnerability in Oracle's E-Business Suite Report Review Agent (RRA) allows arbitrary files to be retrieved with no authentication.
Description
A vulnerability exists in the Oracle E-Business Suite Report Review Agent (RRA). This vulnerability may allow a remote attacker to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. For more information, please see the following documents: |
Impact
A remote attacker may be able to retrieve arbitrary information from Oracle Applications Concurrent Manager servers prior to authentication. |
Solution
Apply a vendor supplied patch. |
Mitigation |
Vendor Information
CVSS Metrics
| Group | Score | Vector |
|---|---|---|
| Base | ||
| Temporal | ||
| Environmental |
References
Acknowledgements
This vulnerability was discovered by Stephen Kost of Integrigy Corporation.
This document was written by Ian A Finlay.
Other Information
| CVE IDs: | None |
| Severity Metric: | 9.38 |
| Date Public: | 2003-04-10 |
| Date First Published: | 2003-04-14 |
| Date Last Updated: | 2003-04-14 16:54 UTC |
| Document Revision: | 15 |