Authentication Bypass Vulnerability in Oracle E-Business Suite
A vulnerability in the communications protocol that Oracle Applications FND File Server (FNDFS) uses can permit an attacker to bypass any OS, database, and application authentication.
April 14, 2003
ReportedApril 11, 2003, by Stephen Kost.
VERSIONS AFFECTED
Oracle E-Business Suite 11i, releases 10.7, 11.0, and11.5.1 through 11.5.8
DESCRIPTION
A vulnerability in the communications protocol that OracleApplications FND File Server (FNDFS) uses can permit an attacker to bypass anyOS, database, and application authentication to retrieve files from OracleApplications Concurrent Manager servers. If the attacker has direct access tothe Concurrent Manager server through SQL*Net, he or she can retrieve sensitivedata or files (e.g., any file accessible by the oracle or applmgr accounts) thatcontain critical passwords.
VENDOR RESPONSE
Oracle has released a securitybulletin regarding this vulnerability and recommends that affected usersdownload and apply the appropriate update.
CREDIT
Discovered by Stephen Kost of IntegrigyCorporation.
About the Author
You May Also Like