Unrated severityNVD Advisory· Published Jul 26, 2005· Updated Apr 16, 2026
CVE-2005-2378
CVE-2005-2378
Description
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
Affected products
1- cpe:2.3:a:oracle:reports:*:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- www.red-database-security.com/advisory/oracle_reports_read_any_file.htmlnvdExploitVendor Advisory
- www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.htmlnvdExploitVendor Advisory
- secunia.com/advisories/18493nvdVendor Advisory
- secunia.com/advisories/18608nvdVendor Advisory
- www.vupen.com/english/advisories/2006/0323nvdVendor Advisory
- marc.infonvd
- marc.infonvd
- securitytracker.com/idnvd
- securitytracker.com/idnvd
- www.securityfocus.com/archive/1/422256/30/7430/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24321nvd
News mentions
0No linked articles in our index yet.