CERT-In Vulnerability Note
CIVN-2003-0005
Buffer Overflow Vulnerability in Oracle E-Business Suite
Original Issue Date:July 26, 2003
Severity Rating: HIGH
Systems Affected
. Oracle E-Business Suite 11i, All Releases . Oracle Applications, All Releases
Overview
A malformed request to FNDWRR CGI program causes FNDWRR executable to crash.
Description
FNDWRR is a program used to view reports and logs in a web browser. FNDWRR is implemented as a CGI program. There exists a buffer overflow in this CGI program which allows the attacker to gain unauthorized access to Oracle E-Business Suite by gaining control over the process and executing the arbitrary code on the server. Any user who has HTTP access and specialized knowledge can exploit this vulnerability over the internet to gain unauthorized access to Oracle E-Business Suite, this can be done by sending a malformed request to FNDWRR CGI causing FNDWRR executable to crash.
Impact This vulnerability may grant an attacker unauthorized access to Oracle E-Business Suite to execute some arbitrary code on the server.
Solution
Oracle has fixed the buffer overflow in the FNDWRR executable and related libraries. The patches number # 2919943 for this vulnerability available at http://metalink.oracle.com . Appropriate testing and backups should be performed before applying any of these patches.
Vendor Information
Oracle Oracle Security Alert 56 Dated: July 23, 2003
http://otn.oracle.com/deploy/security/alerts.htm
References
Oracle
http://otn.oracle.com/deploy/security/pdf/2003alert56.pdf
Integrigy
http://www.integrigy.com/alerts/FNDWRRBufferOverflow.htm
"Best Practices for Keeping Your E-Business Suite Secure" available at
http://metalink.oracle.com
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|