VulnerabilityModified
CVE-2005-2378
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet.
MEDIUM 5.0EPSS 9.11%
Does this matter?
Lower severity and a low EPSS score (9.11%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 9.11% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- oracle/reports
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=112181054226520&w=2
- http://marc.info/?l=bugtraq&m=112181242916757&w=2
- http://secunia.com/advisories/18493Vendor Advisory
- http://secunia.com/advisories/18608Vendor Advisory
- http://securitytracker.com/id?1014525
- http://securitytracker.com/id?1014527
- http://www.red-database-security.com/advisory/oracle_reports_read_any_file.htmlExploit, Vendor Advisory
- http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/422256/30/7430/threaded
- http://www.vupen.com/english/advisories/2006/0323Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321
- http://marc.info/?l=bugtraq&m=112181054226520&w=2
- http://marc.info/?l=bugtraq&m=112181242916757&w=2
- http://secunia.com/advisories/18493Vendor Advisory
- http://secunia.com/advisories/18608Vendor Advisory
- http://securitytracker.com/id?1014525
- http://securitytracker.com/id?1014527
- http://www.red-database-security.com/advisory/oracle_reports_read_any_file.htmlExploit, Vendor Advisory
- http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.htmlExploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/422256/30/7430/threaded
- http://www.vupen.com/english/advisories/2006/0323Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.