Unrated severityNVD Advisory· Published Jul 18, 2005· Updated Apr 16, 2026
CVE-2005-2294
CVE-2005-2294
Description
Oracle Forms 4.5, 6.0, 6i, and 9i on Unix, when a large number of records are retrieved by an Oracle form, stores a copy of the database tables in a world-readable temporary file, which allows local users to gain sensitive information such as credit card numbers.
Affected products
4cpe:2.3:a:oracle:forms:4.5:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:forms:4.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:forms:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:forms:6i:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:forms:9i:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- secunia.com/advisories/15991/nvdPatchVendor Advisory
- www.oracle.com/technology/deploy/security/pdf/cpujul2005.htmlnvdPatchVendor Advisory
- www.red-database-security.com/advisory/oracle_forms_unsecure_temp_file_handling.htmlnvdPatchVendor Advisory
- marc.infonvd
- exchange.xforce.ibmcloud.com/vulnerabilities/21347nvd
News mentions
0No linked articles in our index yet.