Oracle Enterprise Manager Database Control 10.2.0.3, 10.2.0.4; 10.2.0.5, 22.214.171.124, 126.96.36.199, 188.8.131.52
This vulnerability was discovered and researched by Qinglin Jiang of Application Security Inc.
Oracle Enterprise Manager Database Control XML Database Resources page is vulnerable to a Cross-Site scripting vulnerability. An attacker may inject malicious code into the web application and trick a legitimate user to execute it by various methods. The malicious code generally appears in the form of a script and will be executed in the context of the legitimate user. If a legitimate user is in a trusted domain or has already been authenticated, the malicous user may be able to steal session cookies to impersonate a legitimate user and perform some illegal operations on the web application.
Attackers might steal legitimate user’s session cookies to impersonate a legitimate user and perform illegal operations.
Vendor was contacted and a patch was released.
There is no workaround for this vulnerability.
Apply January 2013 CPU.
Vendor Notification – 6/25/2012
Vendor Response – 6/29/2012
Fix – 1/15/2013
Public Disclosure – 20/02/2013