First published: Tue Jul 26 2005(Updated: )
Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via (1) "..", (2) Windows drive letter (C:), and (3) absolute path sequences in the desname parameter. NOTE: this issue was probably fixed by REP06 in CPU Jan 2006, in which case it overlaps CVE-2006-0289.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Reports | =6.0 | |
Oracle Reports | =9i | |
Oracle Reports | =10g | |
Oracle Reports | =6i |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2371 is classified as a critical severity vulnerability due to its potential to allow unauthorized file overwriting.
To fix CVE-2005-2371, ensure you apply the necessary patches provided by Oracle for the affected versions of Oracle Reports.
CVE-2005-2371 affects Oracle Reports versions 6.0, 6i, 9i, and 10g.
Attackers can exploit CVE-2005-2371 to perform directory traversal attacks, enabling them to overwrite arbitrary files.
Yes, CVE-2005-2371 was likely addressed in the CPU January 2006 update for Oracle Reports.