Services
Oracle Audit / Hardening
Security Training
Consulting
Information
Oracle Security Blog
Published Alerts
Upcoming Alerts
Patch Information
Whitepaper
Presentations
Oracle Fact Sheets
Exploits
Tutorials
Videos
Scripts
News & Events
Events
News
Company
Contact
People
Partner
Impressum
Sitemap
Search
|
Various Cross-Site-Scripting Vulnerabilities in Oracle Reports
Name |
Various Cross-Site-Scripting Vulnerabilities in Oracle Reports [REP01], [REP02] |
Severity |
Low Risk |
Category |
Cross Site Scripting (CSS/XSS) |
Vendor URL |
http://www.oracle.com/ |
Author |
Alexander Kornbrust (ak at red-database-security.com) |
Date |
18 July 2006 (V 1.0) |
Details
The Oracle Reports parameters showenv [REP01], parsequery [REP01], cellwrapper [REP02] and delimiter [REP02] are vulnerable against Cross-Site-Scripting.
Affected Products
Internet Application Server
Oracle Application Server
Oracle Developer Suite
Patch Information
Apply Oracle Critical Patch Update October 2006 (CPU July 2006).
History
28-aug-2003 Oracle secalert was informed
29-aug-2003 Bug confirmed
17-oct-2006 Oracle published CPU October 2006
18-oct-2006 Red-Database-Security published this advisory
© 2006 by Red-Database-Security GmbH - last update 18-oct-2006
|
Oracle Reports
Oracle Reports is Oracle's award-winning, high-fidelity enterprise reporting tool.
It enables businesses to give immediate access to information to all levels within and outside
of the organization in an unrivaled scalable and secure environment. Oracle Reports consists of
Oracle Reports Developer (a component of the Oracle Developer Suite) and Oracle Application Server
Reports Services (a component of the Oracle Application Server).
|