This application requires Javascript for optimal performance.

Oracle.Application.Server.Arbitrary.System.Command.Execution

Alias(es)

ORACLE.Reports.Servlet.Command.Execution.Attempt

Release Date

Sep 27, 2005

Severity

high

Impact

Compromise of the affected system.

Description

It indicates a possible exploit of a Servlet Command Execution vulnerability in Oracle Forms.

Oracle Forms starts forms (.fmx files) from arbitrary directories and executes them with Oracle or System user privileges. Attackers can execute arbitrary code by uploading a specially crafted .fmx file and referencing it using an absolute pathname argument.

Affected Products

Oracle Forms 4.5 through 10g

Recommended Actions

Apply the appropriate patch from the vendor or upgrade to a non-vulnerable version if available.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-2372
CVE-2005-2371

Reference/s

http://www.securityfocus.com/bid/14309 (BugTraq)

Reference: VID-10964