CNCVE编号:CNCVE-20010528 CVE编号:CAN-2001-0528 安全级别:高 漏洞中文描述: Oracle E-Business Suite Release 11i Applications Destop Integrator 7.X版中包含FNDPUB11I.DLL版本的调试版本,它把登录APPS的口令放在一个调试文件的纯文本文件中,这允许本地用户获得这些口令并获得权限。 漏洞英文描述: Oracle E-Business Suite Release 11i Applications Desktop Integrator (ADI) version 7.x includes a debug version of FNDPUB11I.DLL, which logs the APPS schema password in cleartext in a debug file, which allows local users to obtain the password and gain privilege. 漏洞参考: Reference: BUGTRAQ:20010507 Oracle's ADI 7.1.1.10.1 Major security hole Reference: URL:http://archives.neohapsis.com/archives/bugtraq/2001-05/0044.html Reference: BUGTRAQ:20010522 Vulnerability in Oracle E-Business Suite Release 11i Applications Des 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误