Oracle.Reports.Server.DESName.Remote.File.Overwrite
Description
This indicates a possible exploit of a Remote File Overwrite vulnerability in Oracle Reports Server. The web interface of Oracle Reports Server is prone to an arbitrary file overwrite vulnerability. An attacker may overwrite files with System-Level or Oracle Applications Server User privileges. This vulnerability could let an attacker cause full database failure, denial of service or even a total system compromise.
Affected Products
Oracle Oracle Reports6i 6.0.8 .19
Oracle Oracle Reports6i 6.0.8
Oracle Oracle Reports 9i
Oracle Oracle Reports 6
Oracle Oracle Reports 10g 9.0.4 .3.3
Oracle Oracle Reports 10g 9.0.4
Oracle Oracle Reports 10g 9.0.3
Oracle Oracle Reports 10g 9.0.2
Oracle Oracle Reports 10g 9.0.1
Oracle Oracle Reports 10g 9.0
Impact
Disclosure or Modification of sensitive system data
Recommended Actions
Apply appropriate patch from the vendor or upgrade to a non-vulnerable version if available.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |