CVE-2011-0836
published 2011-04-20CVE-2011-0836: Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users…
PriorityP417low3.5CVSS 2.0
AVNACMAuSCNIPAN
EXPLOIT
EPSS
3.40%
87.5th percentile
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | enterpriseone_tools | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone_ep | — | — |
| oracle | oneworld_tools | <= 24.1.3 | — |
| oracle | peoplesoft_and_jdedwards_product_suite | — | — |
| oracle | peoplesoft_and_jdedwards_product_suite | — | — |
| oracle | peoplesoft_and_jdedwards_suite_scm | — | — |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88wc-387v-hhv7: Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8
ghsa_unreviewed·2022-05-17
CVE-2011-0836 [LOW] GHSA-88wc-387v-hhv7: Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote authenticated users to affect integrity, related to Web Runtime SEC.
Red Hat
kernel: dccp: handle invalid feature options length
vendor_redhat·2011-05-06·CVSS 7.5
CVE-2011-1770 [HIGH] CWE-190 kernel: dccp: handle invalid feature options length
kernel: dccp: handle invalid feature options length
Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram Congestion Control Protocol (DCCP) packet with an invalid feature options length, which triggers a buffer over-read.
Statement: This issue does not affect Red Hat Enterprise Linux 4 and 5: Red Hat Enterprise Linux 4 does not provide support for the Datagram Congestion Control Protocol (DCCP), and Red Hat Enterprise Linux 5, which does support DCCP, did not backport the upstream commit that introduced this issue, e77b8363b. This has been addressed in Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG via https://rhn.redhat.com/errata/RHSA-2011-0836.html and h
No detection rules found.
Exploit-DB
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/JASMafletMafBrowserClose.mafService?jdemafjasLinkTarget' Cross-Site Scripting
exploitdb·2011-04-19
CVE-2011-0836 Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/JASMafletMafBrowserClose.mafService?jdemafjasLinkTarget' Cross-Site Scripting
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/JASMafletMafBrowserClose.mafService?jdemafjasLinkTarget' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/47479/info
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
* http://XXX.XXX.XXX.XXX/jde/JASMafletMafBrowserClose.mafService
Parameter: jdemafjasLinkTarget
* The GET request has been set
Exploit-DB
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu.maf?jdeowpBackButtonProtect' Cross-Site Scripting
exploitdb·2011-04-19
CVE-2011-0836 Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu.maf?jdeowpBackButtonProtect' Cross-Site Scripting
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu.maf?jdeowpBackButtonProtect' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/47479/info
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
http://XXX.XXX.XXX.XXX/jde/E1Menu.maf
Parameter: jdeowpBackButtonProtect
* The GET request has been set to: >'">alert(20639)
/jde/E1Menu.maf?selec
Exploit-DB
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/MafletClose.mafService?RENDER_MAFLET' Cross-Site Scripting
exploitdb·2011-04-19
CVE-2011-0836 Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/MafletClose.mafService?RENDER_MAFLET' Cross-Site Scripting
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/MafletClose.mafService?RENDER_MAFLET' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/47479/info
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
http://XXX.XXX.XXX.XXX/jde/MafletClose.mafService
Parameter: RENDER_MAFLET
* The GET request has been set to: E1Menu"%2Balert%2844218%29%2B"
/j
Exploit-DB
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_OCL.mafService?e1.namespace' Cross-Site Scripting
exploitdb·2011-04-19
CVE-2011-0836 Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_OCL.mafService?e1.namespace' Cross-Site Scripting
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_OCL.mafService?e1.namespace' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/47479/info
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
http://XXX.XXX.XXX.XXX/jde/E1Menu_OCL.mafService
Parameter: e1.namespace
* The GET request has been set to: %2Balert%2848981%29%2B
/jde/E1Menu_OC
Exploit-DB
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_Menu.mafService?e1.namespace' Cross-Site Scripting
exploitdb·2011-04-19
CVE-2011-0836 Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_Menu.mafService?e1.namespace' Cross-Site Scripting
Oracle JD Edwards EnterpriseOne 8.9x Tools Web Runtime SEC - '/jde/E1Menu_Menu.mafService?e1.namespace' Cross-Site Scripting
---
source: https://www.securityfocus.com/bid/47479/info
Oracle JD Edwards EnterpriseOne is prone to multiple cross-site scripting vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
This vulnerability affects the following supported versions:
8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3
http://XXX.XXX.XXX.XXX/jde/E1Menu_Menu.mafService
Parameter: e1.namespace
* The POST request has been set to: %2Balert%2835890%29%2B
/jde/E1Menu
No writeups or analysis indexed.
2011-04-20
Published