Unrated severityNVD Advisory· Published Jan 18, 2006· Updated Jun 16, 2026
CVE-2006-0275
CVE-2006-0275
Description
Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04. NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the customize parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- cpe:2.3:a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:*
- Range: =9.0.4.2
Patches
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
11- secunia.com/advisories/18493nvdVendor Advisory
- secunia.com/advisories/18608nvdVendor Advisory
- www.kb.cert.org/vuls/id/545804nvdThird Party AdvisoryUS Government Resource
- www.vupen.com/english/advisories/2006/0243nvdVendor Advisory
- www.vupen.com/english/advisories/2006/0323nvdVendor Advisory
- securitytracker.com/idnvd
- www.oracle.com/technetwork/topics/security/cpujan2006-082403.htmlnvd
- www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.htmlnvd
- www.securityfocus.com/archive/1/422261/30/7430/threadednvd
- www.securityfocus.com/bid/16287nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24321nvd
News mentions
0No linked articles in our index yet.