Back
CVE-2005-2378
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
Published: Jul 26, 2005
Modified: Jun 16, 2026
CWE-22
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| oracle | reports | * |
GitHub Security Advisory GHSA-3828-jgm6-f988
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary...
References (22)
- http://marc.info/?l=bugtraq&m=112181054226520&w=2
- http://marc.info/?l=bugtraq&m=112181242916757&w=2
- http://secunia.com/advisories/18493 Vendor Advisory
- http://secunia.com/advisories/18608 Vendor Advisory
- http://securitytracker.com/id?1014525
- http://securitytracker.com/id?1014527
- http://www.red-database-security.com/advisory/oracle_reports_read_any_file.html Exploit, Vendor Advisory
- http://www.red-database-security.com/advisory/oracle_reports_read_any_xml_file.html Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/422256/30/7430/threaded
- http://www.vupen.com/english/advisories/2006/0323 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24321
- http://marc.info/?l=bugtraq&m=112181054226520&w=2
- http://marc.info/?l=bugtraq&m=112181242916757&w=2
- http://secunia.com/advisories/18493 Vendor Advisory
- http://secunia.com/advisories/18608 Vendor Advisory
Risk Scores
CVSS Score
5.0 / 10
EPSS Score
9.11%
Top 5% most likely to be exploited
Threat Score
22.7 / 100
Data Sources
NVD
EPSS
GitHub