High Risk Vulnerability in Oracle Retail Central Office
1 May 2013
Andrew Davies of NCC Group has discovered a High risk vulnerability in Orac=
le Retail Central Office=20
Impact: SQL Injection
Versions affected: Oracle Retail Central Office, versions 13.1, 13.2, 13.3=
, 13.4
Security patch information can be found at the following URL:
http://www.oracle.com/technetwork/topics/security/cpuapr2013-1899555.html
NCC Group is going to withhold details of this flaw for three months. This =
three month window will allow users the time needed to apply the patch befo=
re the details are released to the general public. This reflects the NCC Gr=
oup approach to responsible disclosure.
NCC Group Research
http://www.nccgroup.com/research
For more information please visit <a href=3D"http://www.mimecast.com">http:=
//www.mimecast.com<br>
This email message has been delivered safely and archived online by Mimecas=
t.
</a>