First published: Wed Dec 31 2003(Updated: )
The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle E-Business Suite | =11.3 | |
Oracle E-Business Suite | =11.1 | |
Oracle E-Business Suite | =11.0 | |
Oracle E-Business Suite | =11.6 | |
Oracle E-Business Suite | =11.2 | |
Oracle E-Business Suite | =11.8 | |
Oracle E-Business Suite | =10.7 | |
Oracle E-Business Suite | =11.5 | |
Oracle E-Business Suite | =11.4 | |
Oracle E-Business Suite | =11.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1116 is considered a high severity vulnerability due to its potential for remote exploitation and access to sensitive information.
To fix CVE-2003-1116, it is recommended to apply the latest security patches and updates provided by Oracle for the affected versions of the E-Business Suite.
CVE-2003-1116 affects Oracle E-Business Suite versions 10.7, 11.0, 11.1, 11.2, 11.4, 11.5, 11.6, 11.7, and 11.8.
CVE-2003-1116 can be exploited by remote attackers who can spoof requests to bypass authentication.
The potential consequences of CVE-2003-1116 include unauthorized access to sensitive information and possible manipulation of the Oracle Applications Concurrent Manager.