Oracle JDeveloper Java Business Objects Unspecified
by Carol~
- 4/18/12 8:57 AM
In Reply to: VULNERABILITIES / FIXES - April 18, 2012 by Carol~
Oracle JDeveloper Java Business Objects Unspecified Vulnerability
Release Date : 2012-04-18
Criticality level : Less critical
Impact : Manipulation of data
Where : From local network
Solution Status : Vendor Patch
Software: Oracle Developer Suite 10g
Oracle JDeveloper 10g
Description:
A vulnerability has been reported in Oracle JDeveloper, which can be exploited by malicious people to manipulate certain data.
The vulnerability is caused due to an unspecified error in the Java Business Objects component and can be exploited to update, insert, or delete certain Oracle JDeveloper accessible data.
The vulnerability is reported in version 10.1.3.5.
Solution:
Apply update (please see the vendor's advisory for details).
Provided and/or discovered by:
It is currently unclear who reported this vulnerability as the Oracle Critical Patch Update for April 2012 only provides a bundled list of credits. This section will be updated when/if the original reporter provides more information.
Original Advisory:
http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixFMW
http://secunia.com/advisories/48863/

Moderator
CNET Staff
Samsung Staff
Dell Staff