<?xml version="1.0"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
         xmlns:dc="http://purl.org/dc/elements/1.1/"
         xmlns:syn="http://purl.org/rss/1.0/modules/syndication/"
         xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="http://www.integrigy.com/security-resources/alerts/security-alerts/RSS">
  <title>Security Alerts</title>
  <link>http://www.integrigy.com</link>
  
  <description>
    
       
       
  </description>
  
  
  
            <syn:updatePeriod>daily</syn:updatePeriod>
            <syn:updateFrequency>1</syn:updateFrequency>
            <syn:updateBase>2006-07-18T19:54:09Z</syn:updateBase>
        
  
  <image rdf:resource="http://www.integrigy.com/Integrigy_logo.gif"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/oracle-apps-sql-injection"/>
        
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/fndwrr-vulnerability"/>
        
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/aolj-information-disclosure"/>
        
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/fndfs-vulnerability"/>
        
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/reports-server-password-disclosure"/>
        
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/oracle-applications-search-engines"/>
        
        
            <rdf:li rdf:resource="http://www.integrigy.com/security-resources/alerts/apache-information-disclosure"/>
        
    </rdf:Seq>
  </items>

</channel>

    <item rdf:about="http://www.integrigy.com/security-resources/alerts/oracle-apps-sql-injection">        <title>Oracle E-Business Suite - Multiple SQL Injection Vulnerabilities</title>        <link>http://www.integrigy.com/security-resources/alerts/oracle-apps-sql-injection</link>        <description>Multiple SQL injection vulnerabilities exist in the Oracle E-Business Suite 11i and Oracle Applications 11.0.  These vulnerabilities can be remotely exploited simply using a browser and sending a specially crafted URL to the web server.  A mandatory patch from Oracle is required to solve these security issues.</description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: High</dc:subject>                    <dc:subject>Oracle E-Business Suite</dc:subject>                <dc:date>2006-07-18T02:19:08Z</dc:date>        <dc:type>Page</dc:type>    </item>
    <item rdf:about="http://www.integrigy.com/security-resources/alerts/fndwrr-vulnerability">        <title>Oracle E-Business Suite FNDWRR Buffer Overflow</title>        <link>http://www.integrigy.com/security-resources/alerts/fndwrr-vulnerability</link>        <description>The Oracle Applications FNDWRR CGI program, used to retrieve report output from the Concurrent Manager server via a web browser, has a remotely exploitable buffer overflow.  A mandatory patch from Oracle is required to solve this security issue.</description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: High</dc:subject>                    <dc:subject>Oracle E-Business Suite</dc:subject>                <dc:date>2006-07-18T02:19:17Z</dc:date>        <dc:type>Page</dc:type>    </item>
    <item rdf:about="http://www.integrigy.com/security-resources/alerts/aolj-information-disclosure">        <title>Oracle E-Business Suite AOL/J Setup Test Information Disclosure</title>        <link>http://www.integrigy.com/security-resources/alerts/aolj-information-disclosure</link>        <description></description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: Information</dc:subject>                <dc:date>2006-07-18T02:19:24Z</dc:date>        <dc:type>Page</dc:type>    </item>
    <item rdf:about="http://www.integrigy.com/security-resources/alerts/fndfs-vulnerability">        <title>Oracle E-Business Suite FNDFS Vulnerability</title>        <link>http://www.integrigy.com/security-resources/alerts/fndfs-vulnerability</link>        <description>The Oracle Applications FNDFS program, used to retrieve report output from the Concurrent Manager server, can be used to remotely retrieve any file from the server without operating system or application authentication.  A mandatory patch from Oracle is required to solve this security issue.</description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: High</dc:subject>                <dc:date>2006-07-18T02:19:31Z</dc:date>        <dc:type>Page</dc:type>    </item>
    <item rdf:about="http://www.integrigy.com/security-resources/alerts/reports-server-password-disclosure">        <title>Oracle Reports Server APPS Password Disclosure</title>        <link>http://www.integrigy.com/security-resources/alerts/reports-server-password-disclosure</link>        <description>The Oracle Reports Server may disclose the current APPS password.  Oracle Reports Server is installed as part of the default installation and is used by Oracle Business Intelligence (BIS) and related business intelligence modules (Financial Intelligence, etc.).</description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: High</dc:subject>                <dc:date>2006-07-18T02:19:40Z</dc:date>        <dc:type>Page</dc:type>    </item>
    <item rdf:about="http://www.integrigy.com/security-resources/alerts/oracle-applications-search-engines">        <title>Internet Connected Applications and Search Engines</title>        <link>http://www.integrigy.com/security-resources/alerts/oracle-applications-search-engines</link>        <description>Oracle E-Business Suite self-service applications are often connected to the Internet for direct access by customers, suppliers, and employees. Using search engines (Google, Altavista, etc.) and simple search phrases, hackers can quickly find instances of the Oracle E-Business Suite to attack. All Internet accessible instances of the Oracle E-Business Suite should be shielded from web crawlers and indexing services.  </description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: Information</dc:subject>                    <dc:subject>Oracle E-Business Suite</dc:subject>                <dc:date>2006-07-18T02:19:48Z</dc:date>        <dc:type>Page</dc:type>    </item>
    <item rdf:about="http://www.integrigy.com/security-resources/alerts/apache-information-disclosure">        <title>Information Disclosure through Default Apache Scripts</title>        <link>http://www.integrigy.com/security-resources/alerts/apache-information-disclosure</link>        <description>As part of a default Apache installation, two default cgi-bin scripts, printenv and test-cgi, are installed. Oracle has included these scripts in the installation of 11i. This script provides information regarding the installation, which could be used in an attack.</description>        <dc:publisher>No publisher</dc:publisher>        <dc:creator>ploneadmin</dc:creator>        <dc:rights></dc:rights>                    <dc:subject>Risk: Low</dc:subject>                <dc:date>2006-07-18T02:19:55Z</dc:date>        <dc:type>Page</dc:type>    </item>




</rdf:RDF>
