Advisories Blog | G5 Cyber Security

Zero Day Initiative Advisory 07-016

A vulnerability allows remote attackers to delete any existing Document Management node on vulnerable installations of Oracle E-Business Suite. Authentication is not required to exploit this vulnerability. The specific flaw exists in the APPLSYS.FND_DM_NODES package. The procedure to delete nodes does not check for a valid session thereby allowing an attacker to arbitrarily delete any node registered, including the root node.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/56071/ZDI-07-016.txt

Source: https://packetstormsecurity.com/files/56071/Zero-Day-Initiative-Advisory-07-016.html

Exit mobile version