Vulnerabilities > CVE-2005-2293 - Incomplete Cleanup vulnerability in Oracle Forms Builder 9.0.4

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
oracle
CWE-459
nessus

Summary

Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.

Vulnerable Configurations

Part Description Count
Application
Oracle
1

Common Weakness Enumeration (CWE)

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_118828.NASL
    descriptionSun Management Center 3.5.1: Solaris 8 Oracle Patch. Date this patch was last updated by Sun : Jun/02/05
    last seen2020-06-01
    modified2020-06-02
    plugin id23409
    published2006-11-06
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/23409
    titleSolaris 8 (sparc) : 118828-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_118829.NASL
    descriptionSun Management Center 3.5.1: Solaris 9 Oracle Patch. Date this patch was last updated by Sun : Jun/02/05
    last seen2020-06-01
    modified2020-06-02
    plugin id23549
    published2006-11-06
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/23549
    titleSolaris 9 (sparc) : 118829-04