Vulnerabilities > CVE-2005-2294 - Information Disclosure vulnerability in Forms And Reports

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
oracle
nessus

Summary

Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.

Vulnerable Configurations

Part Description Count
Application
Oracle
4

Nessus

  • NASL familySolaris Local Security Checks
    NASL idSOLARIS8_118828.NASL
    descriptionSun Management Center 3.5.1: Solaris 8 Oracle Patch. Date this patch was last updated by Sun : Jun/02/05
    last seen2020-06-01
    modified2020-06-02
    plugin id23409
    published2006-11-06
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/23409
    titleSolaris 8 (sparc) : 118828-04
  • NASL familySolaris Local Security Checks
    NASL idSOLARIS9_118829.NASL
    descriptionSun Management Center 3.5.1: Solaris 9 Oracle Patch. Date this patch was last updated by Sun : Jun/02/05
    last seen2020-06-01
    modified2020-06-02
    plugin id23549
    published2006-11-06
    reporterThis script is Copyright (C) 2006-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/23549
    titleSolaris 9 (sparc) : 118829-04