[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4b264d78.0506d00a.39c6.43b7@mx.google.com>
Date: Mon, 14 Dec 2009 16:35:37 +0200
From: "Ofer Maor" <ofer.maor@...sp.org>
To: "'Michael Coyne'" <mikeycgto@...online.net>
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: Hacktics Advisory Dec09: Oracle
eBusinessSuite - Multiple Vulnerabilities Allow Remote Takeover
I do not believe there are CVEs for these issues.
According to the correspondence with Oracle, this was never published
(otherwise we would not publish it.)
Oracle's main claim is that this interface was removed in Oracle 12,
however, we still encounter this vulnerability with many of our customers
using the Oracle eBusiness Suite.
Ofer.
From: mikeycgto@...il.com [mailto:mikeycgto@...il.com] On Behalf Of Michael
Coyne
Sent: Monday, December 14, 2009 4:31 PM
To: ofer.maor@...sp.org
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: [Full-disclosure] Hacktics Advisory Dec09: Oracle
eBusinessSuite - Multiple Vulnerabilities Allow Remote Takeover
Anyway you can figure out what are the CVEs for the two Oracle confirmed
issues?
Content of type "text/html" skipped
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists