|
|
|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-2326
The original article can be found at: http://www.securityfocus.com/bid/51482/discuss
|
| |
Vulnerable Systems:
*Oracle JDEdwards 8.98
Oracle JDEdwards is prone to an information-disclosure vulnerability in JD Edwards EnterpriseOne Tools. The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
Attackers can exploit this issue to obtain sensitive information such as the USER, ROLE, ENVIRONMENT tuples that may lead to further attacks.
Vendor Status:
Orcale had since issued an update for this vulnerability
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
CVE Information:
CVE-2011-2326
Disclosure Timeline:
2012-January-23 Rev 3. Updated JD Edwards information for One World Tools SP24
2012-January-18 Rev 2. Updated credit information
2012-January-17 Rev 1. Initial Release
|
|
|
|
|