Oracle Application Server HTTP Response Splitting Vulnerability
BID:15163
Info
Oracle Application Server HTTP Response Splitting Vulnerability
| Bugtraq ID: | 15163 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2005 12:00AM |
| Updated: | Oct 21 2005 12:00AM |
| Credit: | This issue was discovered by Keigo Yamazaki (LAC). |
| Vulnerable: |
Oracle Oracle9i Application Server 9.0.2 .3 Oracle Application Server Release 2 9.0.2 .3 Oracle Application Server 10g 10.1.2 Oracle Application Server 10g 9.0.4 .2 |
| Not Vulnerable: | |
Discussion
Oracle Application Server HTTP Response Splitting Vulnerability
Oracle Application Server is prone to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
This issue was addressed in Oracle Critical Patch Update - October 2005 BID 15134 (Oracle October Security Update Multiple Vulnerabilities). Due to the availability of more information, this vulnerability is being assigned a new BID.
Oracle Application Server is prone to an HTTP response splitting vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote attacker may exploit this vulnerability to influence or misrepresent how Web content is served, cached or interpreted. This could aid in various attacks that attempt to entice client users into a false sense of trust.
This issue was addressed in Oracle Critical Patch Update - October 2005 BID 15134 (Oracle October Security Update Multiple Vulnerabilities). Due to the availability of more information, this vulnerability is being assigned a new BID.
Exploit / POC
Oracle Application Server HTTP Response Splitting Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Oracle Application Server HTTP Response Splitting Vulnerability
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.
Solution:
Oracle has released a Critical Patch Update (Critical Patch Update - October 2005) to address these issues. Information regarding obtaining and applying appropriate patches can be found in the referenced Oracle Critical Patch Update.
References
Oracle Application Server HTTP Response Splitting Vulnerability
References:
References: