Oracle Knowledge Management XXE...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

### Vulnerability Summary The following advisory describe Information Disclosure found in Oracle Knowledge Management version 8.5.1. By enabling searches across a wide variety of sources, Oracle’s InQuira knowledge management products offer simple and convenient ways for users to access knowledge that was once hidden in the myriad systems, applications, and databases used to store enterprise content. Oracle’s products for knowledge management help users find useful knowledge contained in corporate information stores. ### Credit An independent security researcher, Steven Seeley, has reported this vulnerability to Beyond Security’s SecuriTeam Secure Disclosure program. ### Vendor response Oracle has released patches to address this vulnerability, for more details see: http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html. ### Vulnerability Details The vulnerable code can be found in /imws/Result.jsp which when calls, can be used to access an XML from a...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息