CVE-2001-0528: High severity oracle e-business suite vulnerability
Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-0528?
CVE-2001-0528 is considered to have a high severity due to the exposure of the APPS schema password in cleartext.
How do I fix CVE-2001-0528?
To fix CVE-2001-0528, you should remove or disable the debug version of FNDPUB11I.DLL from your Oracle E-Business Suite environment.
Who is affected by CVE-2001-0528?
Organizations using Oracle E-Business Suite Release 11i Applications Desktop Integrator version 7.x are affected by CVE-2001-0528.
What kind of privilege escalation can occur due to CVE-2001-0528?
Local users can exploit CVE-2001-0528 to gain unauthorized access to sensitive operations by obtaining the APPS schema password.
Is CVE-2001-0528 still a relevant vulnerability?
Yes, CVE-2001-0528 remains relevant for any installations of affected Oracle E-Business Suite versions that have not been patched.