Release date:
Updated on:
Affected Systems:
Oracle JDEdwards 8.98
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51482
CVE (CAN) ID: CVE-2011-2326
Oracle JDEdwards is a comprehensive and integrated ERP suite.
The JD Edwards performaniseone Tools Component in Oracle JD Edwards Products 8.98 has an unknown implementation vulnerability. This vulnerability can be exploited through the JDENET protocol and can affect the Enterprise Infrastructure SEC (JDENET) sub-component, after successful exploitation, attackers can leak sensitive information, such as USER, ROLE, and ENVIRONMENT tuples. Affected Versions: 8.98.
<* Source: Oracle
Link: http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Oracle
------
Oracle has released a Security Bulletin (cpujan2012-366304) and patches for this:
Cpujan2012-366304: Oracle Critical Patch Update Advisory-January 2012
Link: http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.html