Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability
BID:4298
Info
Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability
| Bugtraq ID: | 4298 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 15 2002 12:00AM |
| Updated: | Mar 15 2002 12:00AM |
| Credit: | Credited to David Litchfield. |
| Vulnerable: |
Oracle Oracle9i Application Server 1.0.2 |
| Not Vulnerable: | |
Discussion
Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability
Oracle 9iAS package includes the XSQL Servlet as part of the XML Development kit. It may be used to convert the response from an SQL query into an XML format.
Reportedly, the servlet does not properly enforce file permissions. An attacker may be able to exploit this vulnerability to view sensitive system configuration files, similar to the issues discussed in BID 4290.
Oracle 9iAS package includes the XSQL Servlet as part of the XML Development kit. It may be used to convert the response from an SQL query into an XML format.
Reportedly, the servlet does not properly enforce file permissions. An attacker may be able to exploit this vulnerability to view sensitive system configuration files, similar to the issues discussed in BID 4290.
Exploit / POC
Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Oracle 9iAS XSQL Servlet File Permission Bypass Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.