First published: Tue Aug 14 2001(Updated: )
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =11i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0528 is considered to have a high severity due to the exposure of the APPS schema password in cleartext.
To fix CVE-2001-0528, you should remove or disable the debug version of FNDPUB11I.DLL from your Oracle E-Business Suite environment.
Organizations using Oracle E-Business Suite Release 11i Applications Desktop Integrator version 7.x are affected by CVE-2001-0528.
Local users can exploit CVE-2001-0528 to gain unauthorized access to sensitive operations by obtaining the APPS schema password.
Yes, CVE-2001-0528 remains relevant for any installations of affected Oracle E-Business Suite versions that have not been patched.