Oracle Financial Services Analytical... CVE-2018-2660,CVE-2018-2661

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

Vendor description: ------------------- "Oracle is the unchallenged leader in Financial Services, with an integrated, best-in-class, end-to-end solution of intelligent software and powerful hardware designed to meet every financial service need." Source: http://www.oracle.com/us/products/applications/ financial-services/analytical-applications/index.html Business recommendation: ------------------------ By exploiting the XXE vulnerability, an attacker can get read access to the filesystem of the user's system using the OFSAA web application and thus obtain sensitive information from the system. It is also possible to bypass input validation checks in order to inject JavaScript code. SEC Consult recommends to immediately install the patched version. Furthermore, a thorough security review should be performed by security professionals to identify potential further security issues. Vulnerability overview/description: ----------------------------------- #### 1) XML eXternal Entity...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息