This allows remote attackers to affect availability, related to Enterprise Infrastructure SEC (JDENET).
Credit:
The original article can be found at: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-3524
The original article can be found at: http://www.securityfocus.com/bid/51468
Vulnerable Systems:
*Oracle JD Edwards EnterpriseOne Server 9.0
*Oracle JD Edwards EnterpriseOne 8.95 _F1
*Oracle JD Edwards EnterpriseOne 8.95 _B1
*Oracle JD Edwards EnterpriseOne 8.94 _Q1
*Oracle JD Edwards EnterpriseOne 8.98.4.1
*Oracle JD Edwards EnterpriseOne 8.98
*Oracle JD Edwards EnterpriseOne 8.97
*Oracle JD Edwards EnterpriseOne 8.96
*Oracle JD Edwards EnterpriseOne 8.95.J1
*Oracle JD Edwards EnterpriseOne 8.95
*Oracle JD Edwards EnterpriseOne 8.9 GA
Oracle JDEdwards EnterpriseOne Tools is prone to a remote information-disclosure vulnerability.
The vulnerability can be exploited over the 'JDENET' protocol. The 'Enterprise Infrastructure SEC (JDENET)' sub component is affected.
An attacker can exploit this issue to obtain sensitive information from the 'JDE.INI' configuration file
Vendor Status:
Orcale had since issued an update for this vulnerability
Patch Availability:
http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
CVE Information:
CVE-2011-3524
Disclosure Timeline:
2012-January-23 Rev 3. Updated JD Edwards information for One World Tools SP24
2012-January-18 Rev 2. Updated credit information
2012-January-17 Rev 1. Initial Release
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by