Critical flaw found in Oracle developer tool

Article

Critical flaw found in Oracle developer tool

Oracle JInitiator contains a critical flaw that could be exploited by an attacker to execute arbitrary code and compromise a vulnerable system.

The tool is used by developers to run Oracle Developer Server applications directly within Internet Explorer. The flaw was discovered in versions 1.1.8.16 and earlier.

The vulnerability was discovered by Will Dormann of the United States Computer Emergency Readiness Team (US-CERT).

    Requires Free Membership to View

    SearchSecurity.co.UK members gain immediate and unlimited access to breaking UK industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.co.UK today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.co.uk you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.co.uk is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

In the US-CERT advisory, Dormann said the Oracle JInitiator ActiveX control contains multiple stack buffer overflows, which could allow a hacker to conduct an attack remotely. The attacker must trick a user into visiting a malicious website, to conduct the attack.

A patch has not been released. As a workaround, Dormann advised users to disable the Oracle JInitiator ActiveX control in Internet Explorer.

"Installing a later version of the software will not remove the vulnerable version of the control," Dormann said in the advisory. "We are currently unaware of a practical solution to this problem."

Danish security firm Secunia rated the vulnerability "highly critical" in its advisory to customers.