Oracle Clinical Remote Data Capture Option contains an unspecified flaw related to the HTTP Surround subcomponent that may allow an authenticated remote attacker to gain access to potentially sensitive information. No further details have been provided.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified,
Coordinated Disclosure
OSVDB:
Authentication Required,
Web Related
Solution
Currently, there are no known workarounds or upgrades to correct this issue. However, Oracle has released a patch to address this vulnerability. Check the vendor advisory in the references section.