CVE-2003-1116
Status: ModifiedMedium (5)—
The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 4.45%
- Percentile among all scored CVEs: 91
- Score date: 10/8/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://marc.info/?l=bugtraq&m=105012832418415&w=2
- http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf
- http://securitytracker.com/id?1006550
- http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm
- http://www.kb.cert.org/vuls/id/168873
- http://www.securityfocus.com/bid/7325
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11768
- http://marc.info/?l=bugtraq&m=105012832418415&w=2
- http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf
- http://securitytracker.com/id?1006550
- http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm
- http://www.kb.cert.org/vuls/id/168873
- http://www.securityfocus.com/bid/7325
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11768
Raw JSON (NVD)
Show
{
"id": "CVE-2003-1116",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-12-31T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=105012832418415&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1006550",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/168873",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/7325",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11768",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=105012832418415&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://otn.oracle.com/deploy/security/pdf/2003alert53.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1006550",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.integrigy.com/alerts/FNDFS_Vulnerability.htm",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/168873",
"tags": [
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/7325",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11768",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The communications protocol for the Report Review Agent (RRA), aka FND File Server (FNDFS) program, in Oracle E-Business Suite 10.7, 11.0, and 11.5.1 to 11.5.8 allows remote attackers to bypass authentication and obtain sensitive information from the Oracle Applications Concurrent Manager by spoofing requests to the TNS Listener."
}
],
"lastModified": "2026-06-16T22:03:33.323",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:10.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A697B2D5-1F33-47D8-A490-F0DEDD802549"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "120ED075-8649-44F1-A79C-99C040C2E365"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34112DA5-C0B6-46E9-A69F-02F24BDBA6ED"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F6883CFF-B2CB-4B75-8E6B-938A78CF7DFA"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9134636B-0CF6-41BE-8C5F-BB6C0C55A199"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5B512964-2367-4C55-BB75-9EBFB3707179"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1DC2C3EF-B1A4-4BF9-B534-A7ABB6490CCF"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BC900808-1118-4FC0-9E48-380A02394F45"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD00F5CD-125C-4895-824E-23AC1D9A34BF"
},
{
"criteria": "cpe:2.3:a:oracle:e-business_suite:11.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FE95D02-C2A8-4AAC-878B-DFA0FE13B571"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}