Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
BID:3727
Info
Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
| Bugtraq ID: | 3727 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1217 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 20 2001 12:00AM |
| Updated: | Jul 11 2009 09:06AM |
| Credit: | This vulnerability was submitted to BugTraq on December 20th, 2001 by David Litchfield <[email protected]>. |
| Vulnerable: |
Oracle Oracle9i Application Server |
| Not Vulnerable: | |
Discussion
Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
Oracle 9i Application Server comes with an Apache-based web server and support for environments such as SOAP, PL/SQL, XSQL and JSP.
The PL/SQL Apache module for Oracle 9iAS provides functionality for remote
administration of the Database Access Descriptors and access to help pages.
It is possible for a remote attacker to submit a specially crafted web request contained double encoded variations of dot-dot-slash (../) sequences to effectively break out of the 'admin' directory. If the attacker can browse the filesystem of the host, they can display the contents of arbitrary web-readable files.
This is only an issue on Microsoft Windows NT/2000 operating systems. However, since the Apache process runs with SYSTEM privileges, the definition of an arbitrary web-readable file can be interpreted to mean any file of the system which can be displayed in a web browser.
Oracle 9i Application Server comes with an Apache-based web server and support for environments such as SOAP, PL/SQL, XSQL and JSP.
The PL/SQL Apache module for Oracle 9iAS provides functionality for remote
administration of the Database Access Descriptors and access to help pages.
It is possible for a remote attacker to submit a specially crafted web request contained double encoded variations of dot-dot-slash (../) sequences to effectively break out of the 'admin' directory. If the attacker can browse the filesystem of the host, they can display the contents of arbitrary web-readable files.
This is only an issue on Microsoft Windows NT/2000 operating systems. However, since the Apache process runs with SYSTEM privileges, the definition of an arbitrary web-readable file can be interpreted to mean any file of the system which can be displayed in a web browser.
Exploit / POC
Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
Solution:
Oracle has provided a patch which rectifies this issue.
Oracle Oracle9i Application Server
Solution:
Oracle has provided a patch which rectifies this issue.
Oracle Oracle9i Application Server
-
Oracle 2128936
http://metalink.oracle.com
References
Oracle 9I Application Server PL/SQL Apache Module Directory Traversal Vulnerability
References:
References:
- Oracle Security Alert #25 Vulnerabilities in MODPLSQL (Oracle)
- Oracle Support Metalink (Oracle)