Oracle Formsbuilder 9.0.4 stores database usernames and passwords in a temporary file, which is not deleted after it is used, which allows local users to obtain sensitive information.
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/21343 | vdb entry third party advisory |
http://secunia.com/advisories/15991/ | broken link third party advisory patch vendor advisory |
http://marc.info/?l=bugtraq&m=112129452232307&w=2 | mailing list exploit |
http://www.red-database-security.com/advisory/oracle_formsbuilder_temp_file_issue.html | third party advisory exploit |
http://www.oracle.com/technology/deploy/security/pdf/cpujul2005.html | patch vendor advisory broken link |