CVE-2009-1000: High severity oracle e-business suite vulnerability
Published Apr 15, 2009
·Updated
The Oracle Applications Framework component in Oracle E-Business Suite 12.0.6 and 11i10CU2 uses default passwords for unspecified "FND Applications Users (not DB users)," which has unknown impact and attack vectors.
Affected Software
2 affected components
Oracle E-Business Suite=12.0.6
Oracle E-Business Suite=11i10cu2
Event History
Apr 15, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-1000?
CVE-2009-1000 is classified with an unknown severity due to the lack of details on its impact.
2
Which versions are affected by CVE-2009-1000?
CVE-2009-1000 affects Oracle E-Business Suite versions 12.0.6 and 11i10CU2.
3
What is the main issue described in CVE-2009-1000?
CVE-2009-1000 involves the use of default passwords for unspecified 'FND Applications Users' within Oracle E-Business Suite.
4
How do I fix CVE-2009-1000?
To fix CVE-2009-1000, ensure that all default passwords for FND Applications Users are changed to strong, unique passwords.
5
What type of users are impacted by CVE-2009-1000?
CVE-2009-1000 impacts FND Applications Users and does not affect database users.