Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing credentials via a direct request for config/oramon.ini.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Oramon | Oramon | 2.0.1 (including) | 2.0.1 (including) |