Oracle Application Server XML Developer Kit 'Authenticated session' Remote Security Vulnerability
29 Mar. 2011
Summary
Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 11.1.0.7, and 11.2.0.1, and Oracle Fusion Middleware 10.1.3.5, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
Vulnerable Systems:
* Oracle11g Standard Edition 11.1 .7
* Oracle11g Standard Edition 11.2.0.1.0
* Oracle11g Enterprise Edition 11.2.0.1.0
* Oracle11g Enterprise Edition 11.1.0.7
* Oracle10g Standard Edition 10.2 .3
* Oracle10g Standard Edition 10.1 .5
* Oracle10g Standard Edition 10.2.0.4
* Oracle10g Personal Edition 10.2 .3
* Oracle10g Personal Edition 10.1 .5
* Oracle10g Personal Edition 10.2.0.4
* Oracle10g Enterprise Edition 10.2 .3
* Oracle10g Enterprise Edition 10.1 .5
* Oracle10g Enterprise Edition 10.2.0.4
* Oracle10g Application Server 10.1.3 .5.0
* Oracle Application Server 10.1.3.5.0
Oracle Application Server is prone to a remote vulnerability in XML Developer Kit. The vulnerability can be exploited over different protocols. For an exploit to succeed, the attacker must have 'Authenticated session' privileges
Vendor Status:
Oracle as issued an update for this vulnerablity