CVE-2007-2170

The APPLSYS.FND_DM_NODES package in Oracle E-Business Suite does not check for valid sessions, which allows remote attackers to delete arbitrary nodes. NOTE: due to lack of details from Oracle, it is not clear whether this issue is related to other CVE identifiers such as CVE-2007-2126, CVE-2007-2127, or CVE-2007-2128.

Date published : 2007-04-24

http://www.securityfocus.com/archive/1/466214/100/0/threaded

http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuapr2007.html