CVE-2007-2127
published 2007-04-18CVE-2007-2127: Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
2.24%
81.0th percentile
Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library (APPS04), iStore (2) APPS05 and (3) APPS06, (4) iSupport (APPS07), (5) Trade Management (APPS09), (6) Applications Manager (APPS10), and (7) Oracle Report Manager (APPS03).
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | e-business_suite | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-82pq-c8g4-m2jw: Multiple unspecified vulnerabilities in Oracle E-Business Suite 12
ghsa_unreviewed·2022-05-01
CVE-2007-2127 [HIGH] GHSA-82pq-c8g4-m2jw: Multiple unspecified vulnerabilities in Oracle E-Business Suite 12
Multiple unspecified vulnerabilities in Oracle E-Business Suite 12.0.0 have unknown impact and remote attack vectors via (1) Application Object Library (APPS04), iStore (2) APPS05 and (3) APPS06, (4) iSupport (APPS07), (5) Trade Management (APPS09), (6) Applications Manager (APPS10), and (7) Oracle Report Manager (APPS03).
GHSA
GHSA-993q-wpwh-rhvq: The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-2135 [CRITICAL] GHSA-993q-wpwh-rhvq: The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS
The ADI_BINARY component in the Oracle E-Business Suite allows remote attackers to download arbitrary documents from the APPS.FND_DOCUMENTS table via the ADI_DISPLAY_REPORT function, when passed a certain parameter. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
GHSA
GHSA-vrqh-qwvr-mr23: The APPLSYS
ghsa_unreviewed·2022-05-01·CVSS 10.0
CVE-2007-2170 [CRITICAL] GHSA-vrqh-qwvr-mr23: The APPLSYS
The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdfhttp://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_apr_2007.htmlhttp://www.securityfocus.com/archive/1/466329/100/200/threadedhttp://www.securityfocus.com/bid/23532http://www.securitytracker.com/id?1017927http://www.us-cert.gov/cas/techalerts/TA07-108A.htmlhttp://www.vupen.com/english/advisories/2007/1426http://www.integrigy.com/security-resources/analysis/Integrigy_Oracle_CPU_April_2007_Analysis.pdfhttp://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.htmlhttp://www.red-database-security.com/advisory/oracle_cpu_apr_2007.htmlhttp://www.securityfocus.com/archive/1/466329/100/200/threadedhttp://www.securityfocus.com/bid/23532http://www.securitytracker.com/id?1017927http://www.us-cert.gov/cas/techalerts/TA07-108A.htmlhttp://www.vupen.com/english/advisories/2007/1426
2007-04-18
Published