Sensitive Information Exposure via World-Readable Temporary File in Oracle Forms

Sensitive Information Exposure via World-Readable Temporary File in Oracle Forms

CVE-2005-2294 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.

Learn more about our User Device Pen Test.