Oracle OPMN Service Log Format String

Strike ID:
E07-4ah01
CVSS:
10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2007

Description

This strike exploits a format string vulnerability Oracle Application Server's Oracle Process Manager and Notification's logging function. An attacker may send a format string to OPMN service, causing the component to either crash or execute malicious code.

CVE

References

Bid