rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Application_server | Oracle | 9.0.2 (including) | 9.0.2 (including) |
Reports | Oracle | 6.0.8 (including) | 6.0.8 (including) |
Reports | Oracle | 6.0.8.19 (including) | 6.0.8.19 (including) |