Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability

BID:5119

Info

Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability

Bugtraq ID: 5119
Class: Access Validation Error
CVE:
Remote: Yes
Local: No
Published: Jun 28 2002 12:00AM
Updated: Jun 28 2002 12:00AM
Credit: Discovered by Matt Moore <[email protected]>.
Vulnerable: Sybase Enterprise Application Server 4.0
Pramati Pramati Server 3.0
Orion* Orion Application Server 1.5.3
Oracle Oracle9i Application Server 9.0.2 .0.1
Oracle Oracle9i Application Server 9.0.2 .0.0
Oracle Oracle9i Application Server 9.0.2
Oracle Oracle9i Application Server 1.0.2 .2
Oracle E-Business Suite 11i 11.8
Oracle E-Business Suite 11i 11.7
Oracle E-Business Suite 11i 11.6
Oracle E-Business Suite 11i 11.5
Oracle E-Business Suite 11i 11.4
Oracle E-Business Suite 11i 11.3
Oracle E-Business Suite 11i 11.2
Oracle E-Business Suite 11i 11.1
Macromedia JRun 4.0
- Microsoft IIS 5.1
- Microsoft IIS 5.0
- Microsoft IIS 4.0
Macromedia JRun 3.1
- IBM AIX 4.3
- IBM AIX 4.2
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP5
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
- Redhat Linux 6.1 sparc
- Redhat Linux 6.1 i386
- Redhat Linux 6.1 alpha
- Redhat Linux 6.0 sparc
- Redhat Linux 6.0 alpha
- Redhat Linux 6.0
- SGI IRIX 6.5
- Sun Solaris 8_sparc
- Sun Solaris 7.0
Macromedia JRun 3.0
- IBM AIX 4.3
- IBM AIX 4.2
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional
- Microsoft Windows 95
- Microsoft Windows 98
- Microsoft Windows NT 4.0 SP6a
- Microsoft Windows NT 4.0 SP6
- Microsoft Windows NT 4.0 SP4
- Microsoft Windows NT 4.0 SP3
- Microsoft Windows NT 4.0 SP2
- Microsoft Windows NT 4.0 SP1
- Microsoft Windows NT 4.0
- Redhat Linux 6.1 sparc
- Redhat Linux 6.1 i386
- Redhat Linux 6.1 alpha
- Redhat Linux 6.0 sparc
- Redhat Linux 6.0
- SGI IRIX 6.5
- Sun Solaris 7.0
- Sun Solaris 2.6
jo! jo Webserver 1.0 rc1
HP Application Server 8.0
Not Vulnerable: Sybase Enterprise Application Server 4.1
Orion* Orion Application Server 1.5.4
Oracle Oracle9i Application Server 9.0.3
Oracle Oracle9i Application Server 9.0.2
jo! jo Webserver 1.0 b7

Discussion

Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability

An issue has been discovered in Sybase Enterprise Application Server, Oracle9i Application Server with OC4J, Orion Server, Macromedia/Allaire JRun, HP Application Server, Pramati Application Server and jo! Webserver.

Submitting a malformed request for the restricted WEB-INF directory will reveal highly sensitive system content to remote users.

Obtaining information within this directory could result in the disclosure of highly sensitive data that could be used to leverage further attacks against the host.

Exploit / POC

Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability

No exploit code is required.

Solution / Fix

Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability

Solution:
Orion* has addressed this issue in Orion Server 1.5.4.

Macromedia has released a fix for JRun.

Oracle9iAS Release 2 v9.0.2 addresses this issue:
http://otn.oracle.com/software/products/ias/devuse.html

This issue has been addressed in Oracle9iAS Release 2 v9.0.2.0.1 for Windows NT and Oracle9iAS Release 2 v9.0.3 for Unix platforms.

Oracle has also stated that versions of E-Business Suite 11i may be affected by this issue. See referenced advisory for additional information.

Sybase has addressed this issue in Enterprise Application Server 4.1.

jo! jo Webserver has addressed this issue in 1.0b7.

Reportedly, HP will address this issue in MP8 and Pramati Application Server will be fixed with SP1. The release date of these fixes are not yet known.


jo! jo Webserver 1.0 rc1

Orion* Orion Application Server 1.5.3

Macromedia JRun 3.0

Macromedia JRun 3.1

Macromedia JRun 4.0

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report