|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2302
The original article can be found at: http://www.securityfocus.com/bid/50221/discuss
|
| |
Vulnerable Systems:
* Oracle E-Business Suite 12 12.1.2
* Oracle E-Business Suite 12 12.0.6
* Oracle E-Business Suite 12 12.1.3
* Oracle E-Business Suite 11i 11.5.10.2
Oracle E-Business Suite is prone to a remote vulnerability in Oracle Application Object Library.
The vulnerability can be exploited over the 'HTTP' protocol. The 'Single Sign On' sub component is affected.
Vendor Status:
Oracle has issued an update to correct this vulnerability.
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html
CVE Information:
CVE-2011-2302
Disclosure Timeline:
2011-November-10 Rev 4. Changed CVSS Score for CVE-2011-3512 to 6.5
2011-October-20 Rev 3. Changed CVSS Score for CVE-2011-2301 to 8.5
2011-October-18 Rev 2. Changed CVE for Oracle Thesaurus Management System from CVE-2011-3538 to CVE-2011-2323
2011-October-18 Rev 1. Initial Release
|
|
|