First published: Sat Aug 02 2003(Updated: )
Buffer overflow in the Oracle Applications Web Report Review (FNDWRR) CGI program (FNDWRR.exe) of Oracle E-Business Suite 11.0 and 11.5.1 through 11.5.8 may allow remote attackers to execute arbitrary code via a long URL.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =11.3 | |
Oracle E-Business Suite | =11.1 | |
Oracle Applications | =10.7 | |
Oracle E-Business Suite | =11.6 | |
Oracle E-Business Suite | =11.2 | |
Oracle E-Business Suite | =11.8 | |
Oracle E-Business Suite | =11.5 | |
Oracle E-Business Suite | =11.4 | |
Oracle E-Business Suite | =11.7 | |
Oracle Applications | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0632 is considered critical due to its potential to allow remote code execution.
To mitigate CVE-2003-0632, you should apply the appropriate patches provided by Oracle for affected versions of E-Business Suite.
CVE-2003-0632 affects Oracle E-Business Suite versions 11.0 to 11.5.8 and Oracle Applications version 10.7.
CVE-2003-0632 is classified as a buffer overflow vulnerability.
CVE-2003-0632 can be exploited by remote attackers who can send specially crafted requests to the vulnerable application.