Vulnerability Name:

CVE-2005-2294 (CCN-21347)

Assigned:2005-07-12
Published:2005-07-12
Updated:2017-07-11
Summary:Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2005-2294

Source: BUGTRAQ
Type: UNKNOWN
20050713 Advisory: Oracle Forms Insecure Temporary File Handling

Source: CCN
Type: SA15991
Oracle Products Multiple Unspecified Vulnerabilities

Source: SECUNIA
Type: Patch, Vendor Advisory
15991

Source: CCN
Type: Oracle Critical Patch Update Advisory dated July 2005
Oracle Critical Patch Update - July 2005

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html

Source: CCN
Type: Oracle9i Forms Web site
Oracle9i Forms Technical Information

Source: CCN
Type: OSVDB ID: 18246
Oracle Application Server Forms 'buffered records' Temp File Information Disclosure

Source: CCN
Type: Red-Database-Security Advisory AKSEC2003-006
Oracle Forms Insecure Temporary File Handling

Source: MISC
Type: Patch, Vendor Advisory
http://www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.html

Source: XF
Type: UNKNOWN
formsbuilder-temp-file-info-disclosure(21347)

Source: XF
Type: UNKNOWN
formsbuilder-temp-file-info-disclosure(21347)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:forms:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:forms:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:forms:6i:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:forms:9i:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:forms:4.5:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:forms:6.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:forms:6i:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:forms:9i:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle forms 4.5
    oracle forms 6.0
    oracle forms 6i
    oracle forms 9i
    oracle forms 4.5
    oracle forms 6.0
    oracle forms 6i
    oracle forms 9i