|
|
| |
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-0528
The original article can be found at: http://www.securityfocus.com/bid/53089
|
| |
Vulnerable Systems:
* Oracle Oracle11g Standard Edition 11.1.0.7 R1
* Oracle Oracle11g Enterprise Edition 11.1.0.7 R1
* Oracle Oracle10g Standard Edition 10.2 .5
* Oracle Oracle10g Standard Edition 10.2 .3 R2
* Oracle Oracle10g Standard Edition 10.2.0.4 R2
* Oracle Oracle10g Personal Edition 10.2 .5
* Oracle Oracle10g Personal Edition 10.2 .3 R2
* Oracle Oracle10g Personal Edition 10.2.0.4 R2
* Oracle Oracle10g Enterprise Edition 10.2 .5
* Oracle Oracle10g Enterprise Edition 10.2 .3 R2
* Oracle Oracle10g Enterprise Edition 10.2.0.4 R2
The vulnerability can be exploited over the 'HTTP' protocol. The 'Security Framework' sub component is affected.
An attacker can exploit this issue to hijack an arbitrary session and gain unauthorized access to the affected application.
Vendor Status:
Oracle as issued an update for this vulnerablity
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html
CVE Information:
CVE-2012-0528
Disclosure Timeline:
2012-April-17 Rev 1. Initial Release
|
|
|