Update Protection against Oracle Reports Arbitrary File Reading Vulnerability
| Check Point Reference: | CPAI-2006-037 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | US-CERT VU#925261 | |
| Industry Reference(s): |
CVE-2005-2378 |
|
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Oracle Reports Server | ||
| Vulnerability Description Oracle Reports is an enterprise reporting tool that extracts data from multiple sources and inserts it into a formatted report. Oracle Reports fails to validate URI parameters, possibly allowing a remote attacker to read arbitrary files on the Reports Server. |
||
|
Update/Patch Available This issue is corrected in the Oracle Critical Patch Update for January 2006. |
|
|
Vulnerability Details Oracle Reports is a component of Oracle Application Server and the Oracle Developer Suite. Oracle Reports are accessible over a network via a URI. Improper validation on the desformat URI parameter could allow a remote attacker to read arbitrary files on the Oracle Reports Server. |
Protection Overview
The Update enables the HTTP Worm Catcher to detect and block the vulnerability based on pre-defined worm signatures.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The update from April 27, 2006 includes the following protections:
MS-RPC Protections Enforced on TCP Ports (CPSA-2006-03)
Oracle Reports/Forms Vulnerability (CPAI-2006-037)
IPSwitch WhatUp Professional DoS (CPAI-2006-038)
Multiple Products LDAP Vulnerabilities (CPAI-2006-039)
Multiple Products FTP Servers Vulnerabilities (CPAI-2006-040)