Back to search
CVE-2007-2135
Published: Apr 24, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
2612
third-party-advisory
x_refsource_SREASON
20070418 ZDI-07-017: Oracle E-Business Suite Arbitrary Document Download Vulnerability
mailing-list
x_refsource_BUGTRAQ
http://www.zerodayinitiative.com/advisories/ZDI-07-017.html
x_refsource_MISC
39959
vdb-entry
x_refsource_OSVDB
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now