Oracle Configurator System Information Leak Vulnerability
BID:4433
Info
Oracle Configurator System Information Leak Vulnerability
| Bugtraq ID: | 4433 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 01 2002 12:00AM |
| Updated: | Apr 01 2002 12:00AM |
| Credit: | Published in Oracle Security Alert #31. |
| Vulnerable: |
Oracle Configurator 11.0 i |
| Not Vulnerable: | |
Discussion
Oracle Configurator System Information Leak Vulnerability
An issue has been discovered in Oracle Configurator, which could allow a remote user to gain knowledge of sensitive system information.
This issue is achievable when submitting certain requests to the 'oracle.apps.cz.servlet.UiServlet' servlet. The host can be led to reveal the version, hostname and port information.
This information can be used to assist in further attacks against the host.
An issue has been discovered in Oracle Configurator, which could allow a remote user to gain knowledge of sensitive system information.
This issue is achievable when submitting certain requests to the 'oracle.apps.cz.servlet.UiServlet' servlet. The host can be led to reveal the version, hostname and port information.
This information can be used to assist in further attacks against the host.
Solution / Fix
Oracle Configurator System Information Leak Vulnerability
Solution:
Oracle has released CZ patchset H, and in builds 17.32 and 16.53. Contact Oracle support for further information on obtaining the fix. In addition, for this fix to be active, you must add the following line to your jserv.properties file: oracle.apps.cz.uiservlet.versionFuncsAvail=false
Solution:
Oracle has released CZ patchset H, and in builds 17.32 and 16.53. Contact Oracle support for further information on obtaining the fix. In addition, for this fix to be active, you must add the following line to your jserv.properties file: oracle.apps.cz.uiservlet.versionFuncsAvail=false