Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
http://www.oracle.com/technetwork/topics/security/cpuoct2012-1515893.html | patch vendor advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2013:150 | vendor advisory broken link |