Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to version or host.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Configurator | Oracle | 11.5.6.0.0 (including) | 11.5.6.16.53 (including) |
Configurator | Oracle | 11.5.7.0.0 (including) | 11.5.7.17.31 (including) |
Configurator | Oracle | 11i (including) | 11i (including) |