CVE-2007-2170
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
- CVSS 2.0
- 9.4 HIGHAV:N/AC:L/Au:N/C:N/I:C/A:C
- EPSS
- 3.86% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- oracle/e-business suite
- Source
- cve@mitre.org
References
- http://osvdb.org/39958
- http://securityreason.com/securityalert/2611
- http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.htmlPatch
- http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.htmlPatch
- http://www.securityfocus.com/archive/1/466214/100/0/threaded
- http://www.zerodayinitiative.com/advisories/ZDI-07-016.htmlPatch
- http://osvdb.org/39958
- http://securityreason.com/securityalert/2611
- http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.htmlPatch
- http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.htmlPatch
- http://www.securityfocus.com/archive/1/466214/100/0/threaded
- http://www.zerodayinitiative.com/advisories/ZDI-07-016.htmlPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.