|
Brought to you by:
Suppliers of:
|
|
|
| |
| The parameter NOTIFCATION_MSG parameter contains a cross site scripting vulnerability. |
| |
Credit:
The information has been provided by Alexander Kornbrust.
The original article can be found at: http://www.red-database-security.com/advisory/oracle_apex_css_notification_msg.html
|
| |
Affected Products:
* Oracle APEX/HTMLDB versions prior to 2.2.1
Patch Information:
This bug is fixed with the patch 2.2.1 of APEX which is not part of the Critical Patch Update October 2006. It's necessary to upgrade your APEX/HTMLDB installation to 2.2.1. Patches are currently not available for Oracle Application Express.
History:
03-oct-2005 Oracle secalert was informed
04-oct-2005 Bug confirmed
17-oct-2006 Oracle published CPU October 2006
18-oct-2006 Red-Database-Security published this advisory
23-oct-2006 CVE added
CVE Information:
CVE-2006-5351
|
|
|
|
|