CVE-2007-2126
published 2007-04-18CVE-2007-2126: Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2)…
PriorityP431critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.24%
81.0th percentile
Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2) iProcurement (APPS02).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-993q-wpwh-rhvq: The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-2135 [CRITICAL] GHSA-993q-wpwh-rhvq: The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS
The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
GHSA
GHSA-vrqh-qwvr-mr23: The APPLSYS
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-2170 [CRITICAL] GHSA-vrqh-qwvr-mr23: The APPLSYS
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
GHSA
GHSA-hvmw-63v6-mpv5: Unspecified vulnerability in Oracle E-Business Suite 11
ghsa_unreviewed·2022-05-01
CVE-2007-2126 [HIGH] GHSA-hvmw-63v6-mpv5: Unspecified vulnerability in Oracle E-Business Suite 11
Unspecified vulnerability in Oracle E-Business Suite 11.5.10CU2 has unknown impact and remote attack vectors in the (1) Common Applications (APPS01) and (2) iProcurement (APPS02).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdfhttp://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_apr_2007.htmlhttp://www.securityfocus.com/archive/1/466329/100/200/threadedhttp://www.securityfocus.com/bid/23532http://www.securitytracker.com/id?1017927http://www.us-cert.gov/cas/techalerts/TA07-108A.htmlhttp://www.vupen.com/english/advisories/2007/1426http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdfhttp://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_apr_2007.htmlhttp://www.securityfocus.com/archive/1/466329/100/200/threadedhttp://www.securityfocus.com/bid/23532http://www.securitytracker.com/id?1017927http://www.us-cert.gov/cas/techalerts/TA07-108A.htmlhttp://www.vupen.com/english/advisories/2007/1426
2007-04-18
Published