CVE-2007-2170: Critical severity Oracle E-Business Suite vulnerability
The APPLSYS.FNDDMNODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2170?
CVE-2007-2170 is considered a serious vulnerability due to its potential to allow unauthorized deletion of arbitrary nodes in Oracle E-Business Suite.
How do I fix CVE-2007-2170?
To fix CVE-2007-2170, apply the latest patch provided in the Oracle Critical Patch Update for April 2007.
What systems are affected by CVE-2007-2170?
CVE-2007-2170 affects the Oracle E-Business Suite software.
Can CVE-2007-2170 be exploited remotely?
Yes, CVE-2007-2170 can be exploited remotely without needing valid session authentication.
What is the main issue with CVE-2007-2170?
The main issue with CVE-2007-2170 is the lack of session validation in the APPLSYS.FND_DM_NODES package, allowing unauthorized operations.