Attack (Attack ID:319409)

Release Date2014/08/12

Attack NameWEB Oracle Business Intelligence Mobile App Designer Information Disclosure (CVE-2014-4249)

Severity

BUG ID

CVE ID

 

Description

The vulnerability is due to insufficient input validation of certain parameters, which can allow an attacker to traverse the file system and access files.
Impact:Remote code execution
Affected System:Windows, Linux, FreeBSD, Solaris, Other Unix, Mac OS
Additional References:CVE-2014-4249

 

Solution

Update vendor's patch.