First published: Sat Aug 02 2003(Updated: )
Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =11.3 | |
Oracle E-Business Suite | =11.1 | |
Oracle Applications | =10.7 | |
Oracle E-Business Suite | =11.6 | |
Oracle E-Business Suite | =11.2 | |
Oracle E-Business Suite | =11.8 | |
Oracle E-Business Suite | =11.5 | |
Oracle E-Business Suite | =11.4 | |
Oracle E-Business Suite | =11.7 | |
Oracle Applications | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0633 allows remote attackers to gain access to sensitive information without authentication, including the GUEST user password and application server security key.
To determine if your system is affected by CVE-2003-0633, check if you are using Oracle E-Business Suite versions 11.5.1 through 11.5.8 or Oracle Applications versions 10.7 or 11.0.
The recommended fix for CVE-2003-0633 involves applying the latest security patches from Oracle for the affected versions.
While a specific workaround for CVE-2003-0633 is not detailed, minimizing remote access and securing application endpoints can help mitigate risks.
CVE-2003-0633 is categorized with a high severity rating due to the potential for unauthorized access to sensitive information.