Oracle 9i Application Server Path Revealing Vulnerability
BID:3341
Info
Oracle 9i Application Server Path Revealing Vulnerability
| Bugtraq ID: | 3341 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 17 2001 12:00AM |
| Updated: | Sep 17 2001 12:00AM |
| Credit: | This vulnerability was posted to BugTraq by KK Mookhey <[email protected]>. |
| Vulnerable: |
Oracle Oracle9i Application Server 1.0.2 |
| Not Vulnerable: | |
Discussion
Oracle 9i Application Server Path Revealing Vulnerability
Oracle 9i Application Server comes with an Apache-based web server and Java servlet engine.
A vulnerability exists that could allow a malicious user to view the full path to the web folder by sending the server an HTTP request for a non-existant .jsp file. This request could cause the server to send an error message revealing the web folder path information.
A similar vulnerability was found in Apache Tomcat 3.1 which may be related to this vulnerability. See BugTraq ID 1531 for details.
Oracle 9i Application Server comes with an Apache-based web server and Java servlet engine.
A vulnerability exists that could allow a malicious user to view the full path to the web folder by sending the server an HTTP request for a non-existant .jsp file. This request could cause the server to send an error message revealing the web folder path information.
A similar vulnerability was found in Apache Tomcat 3.1 which may be related to this vulnerability. See BugTraq ID 1531 for details.
Exploit / POC
Oracle 9i Application Server Path Revealing Vulnerability
This vulnerability can be exploited using a web browser.
This vulnerability can be exploited using a web browser.
Solution / Fix
Oracle 9i Application Server Path Revealing Vulnerability
Solution:
As a solution to this problem, Oracle recommends upgrading to OJSP 1.1.2.0.0, which can be obtained here:
http://otn.oracle.com/software/tech/java/servlets/content.html
Oracle Oracle9i Application Server 1.0.2
Solution:
As a solution to this problem, Oracle recommends upgrading to OJSP 1.1.2.0.0, which can be obtained here:
http://otn.oracle.com/software/tech/java/servlets/content.html
Oracle Oracle9i Application Server 1.0.2
-
Oracle OJSP 1.2.2.0.0
http://otn.oracle.com/software/tech/java/servlets/content.html
References
Oracle 9i Application Server Path Revealing Vulnerability
References:
References:
- BugTraq ID 1531: Apache Tomcat 3.1 Path Revealing Vulnerability (SecurityFocus)
- Oracle 9i Application Server (Oracle)
- Oracle Unintended JSP Execution Vulnerability (Oracle)