Oracle 9IAS OracleJSP Information Disclosure Vulnerability
BID:4034
Info
Oracle 9IAS OracleJSP Information Disclosure Vulnerability
| Bugtraq ID: | 4034 |
| Class: | Design Error |
| CVE: |
CVE-2002-0562 CVE-2002-0565 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 06 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This issue was publicized in a NGSSoftware Insight Security Research Advisory on February 6th, 2002. |
| Vulnerable: |
Stonesoft StoneBeat GUI 2.0 .0.3 Oracle Oracle9i Standard Edition 9.0.1 Oracle Oracle9i Standard Edition 9.0 Oracle Oracle9i Application Server Web Cache 2.0 .0.3 Oracle Oracle9i Application Server Web Cache 2.0 .0.2 Oracle Oracle9i Application Server Web Cache 2.0 .0.1 Oracle Oracle9i Application Server Web Cache 2.0 .0.0 Oracle Oracle9i Application Server |
| Not Vulnerable: | |
Discussion
Oracle 9IAS OracleJSP Information Disclosure Vulnerability
The Oracle 9iAS web service is powered by the Apache webserver. Included is support for delivery of JSP pages.
Three files are created when a user requests a JSP page from a server running OracleJSP. These files contain potentially sensitive information. For example, if a file was named file.jsp, the naming convention for the files is as follows:
_file$__jsp_StaticText.class
_file.class
_file.java
These files are stored in the /_pages directory tree. The problem is that .java file contains source code and may be accessed by arbitrary web users. This may result in the disclosure of database authentication credentials to any user who can guess the path to the untranslated .java file, in addition to disclosing other types of potentially sensitive information.
Furthermore, globals.jsa files may be accessed in this manner, also potentially disclosing sensitive information to remote attackers.
The Oracle 9iAS web service is powered by the Apache webserver. Included is support for delivery of JSP pages.
Three files are created when a user requests a JSP page from a server running OracleJSP. These files contain potentially sensitive information. For example, if a file was named file.jsp, the naming convention for the files is as follows:
_file$__jsp_StaticText.class
_file.class
_file.java
These files are stored in the /_pages directory tree. The problem is that .java file contains source code and may be accessed by arbitrary web users. This may result in the disclosure of database authentication credentials to any user who can guess the path to the untranslated .java file, in addition to disclosing other types of potentially sensitive information.
Furthermore, globals.jsa files may be accessed in this manner, also potentially disclosing sensitive information to remote attackers.
Exploit / POC
Oracle 9IAS OracleJSP Information Disclosure Vulnerability
This issue may be exploited with a web browser.
This issue may be exploited with a web browser.
Solution / Fix
Oracle 9IAS OracleJSP Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Oracle Oracle9i Application Server
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Oracle Oracle9i Application Server
-
Oracle 2128936
http://metalink.oracle.com
References
Oracle 9IAS OracleJSP Information Disclosure Vulnerability
References:
References: