Oracle Database Server UTL_FILE Directory Traversal File Access
Medium Nessus Network Monitor Plugin ID 2680
The remote host is vulnerable to a flaw that allows attackers to retrieve sensitive files.
The remote host appears to be running a vulnerable version of Oracle Database Server. An authenticated user can craft SQL queries such that they would be able to retrieve any file on the system. An attacker exploiting this flaw would need a valid account and would need to be able to connect to the Oracle service (typically on port 2972). The attacker would retrieve and/or potentially modify confidential data on the target Oracle server.
Upgrade or patch according to vendor recommendations.