Description
netinfiltration reported various high severity vulnerabilities (and exploits) affecting Oracle Reports. These vulnerabilities allow an attacker to dump the database passwords, view folder contents, download files, load a phishing page in the browser and even gain a remote shell.
Remediation
Currently, Oracle didn't provided any fix for these vulnerabilities.
References
Related Vulnerabilities
Unauthenticated remote code execution vulnerability in Confluence Server and Data Center
phpThumb() fltr[] parameter command injection vulnerability
WordPress Plugin WP E-Signature Remote Code Execution (1.5.6.5)
ColdFusion Access Control bypass with WDDX Deserialization RCE (CVE-2023-29298/CVE-2023-29300)