Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
BID:5119
Info
Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
| Bugtraq ID: | 5119 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 28 2002 12:00AM |
| Updated: | Jun 28 2002 12:00AM |
| Credit: | Discovered by Matt Moore <[email protected]>. |
| Vulnerable: |
Sybase Enterprise Application Server 4.0 Pramati Pramati Server 3.0 Orion* Orion Application Server 1.5.3 Oracle Oracle9i Application Server 9.0.2 .0.1 Oracle Oracle9i Application Server 9.0.2 .0.0 Oracle Oracle9i Application Server 9.0.2 Oracle Oracle9i Application Server 1.0.2 .2 Oracle E-Business Suite 11i 11.8 Oracle E-Business Suite 11i 11.7 Oracle E-Business Suite 11i 11.6 Oracle E-Business Suite 11i 11.5 Oracle E-Business Suite 11i 11.4 Oracle E-Business Suite 11i 11.3 Oracle E-Business Suite 11i 11.2 Oracle E-Business Suite 11i 11.1 Macromedia JRun 4.0 Macromedia JRun 3.1 Macromedia JRun 3.0 jo! jo Webserver 1.0 rc1 HP Application Server 8.0 |
| Not Vulnerable: |
Sybase Enterprise Application Server 4.1 Orion* Orion Application Server 1.5.4 Oracle Oracle9i Application Server 9.0.3 Oracle Oracle9i Application Server 9.0.2 jo! jo Webserver 1.0 b7 |
Discussion
Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
An issue has been discovered in Sybase Enterprise Application Server, Oracle9i Application Server with OC4J, Orion Server, Macromedia/Allaire JRun, HP Application Server, Pramati Application Server and jo! Webserver.
Submitting a malformed request for the restricted WEB-INF directory will reveal highly sensitive system content to remote users.
Obtaining information within this directory could result in the disclosure of highly sensitive data that could be used to leverage further attacks against the host.
An issue has been discovered in Sybase Enterprise Application Server, Oracle9i Application Server with OC4J, Orion Server, Macromedia/Allaire JRun, HP Application Server, Pramati Application Server and jo! Webserver.
Submitting a malformed request for the restricted WEB-INF directory will reveal highly sensitive system content to remote users.
Obtaining information within this directory could result in the disclosure of highly sensitive data that could be used to leverage further attacks against the host.
Exploit / POC
Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
Solution:
Orion* has addressed this issue in Orion Server 1.5.4.
Macromedia has released a fix for JRun.
Oracle9iAS Release 2 v9.0.2 addresses this issue:
http://otn.oracle.com/software/products/ias/devuse.html
This issue has been addressed in Oracle9iAS Release 2 v9.0.2.0.1 for Windows NT and Oracle9iAS Release 2 v9.0.3 for Unix platforms.
Oracle has also stated that versions of E-Business Suite 11i may be affected by this issue. See referenced advisory for additional information.
Sybase has addressed this issue in Enterprise Application Server 4.1.
jo! jo Webserver has addressed this issue in 1.0b7.
Reportedly, HP will address this issue in MP8 and Pramati Application Server will be fixed with SP1. The release date of these fixes are not yet known.
jo! jo Webserver 1.0 rc1
Orion* Orion Application Server 1.5.3
Macromedia JRun 3.0
Macromedia JRun 3.1
Macromedia JRun 4.0
Solution:
Orion* has addressed this issue in Orion Server 1.5.4.
Macromedia has released a fix for JRun.
Oracle9iAS Release 2 v9.0.2 addresses this issue:
http://otn.oracle.com/software/products/ias/devuse.html
This issue has been addressed in Oracle9iAS Release 2 v9.0.2.0.1 for Windows NT and Oracle9iAS Release 2 v9.0.3 for Unix platforms.
Oracle has also stated that versions of E-Business Suite 11i may be affected by this issue. See referenced advisory for additional information.
Sybase has addressed this issue in Enterprise Application Server 4.1.
jo! jo Webserver has addressed this issue in 1.0b7.
Reportedly, HP will address this issue in MP8 and Pramati Application Server will be fixed with SP1. The release date of these fixes are not yet known.
jo! jo Webserver 1.0 rc1
Orion* Orion Application Server 1.5.3
-
Orion* orion1.5.4
http://www.orionserver.com/mirrordownload.jsp?file=orion1.5.4.zip
Macromedia JRun 3.0
-
Macromedia jrun-30-unix-upgrade-us_49297.sh
Patch for Macromedia JRun 3.0/UNIX and Linux systems.
http://download.macromedia.com/pub/security/jrun/30/unix/jrun-30-unix- upgrade-us_49297.sh -
Macromedia jrun-30-win-upgrade-en_49297.exe
Patch for Macromedia JRun 3.0/Windows systems.
http://download.macromedia.com/pub/security/jrun/30/intel-win/jrun-30- win-upgrade-en_49297.exe
Macromedia JRun 3.1
-
Macromedia jrun-31-unix-upgrade-us_49297.sh
Patch for Macromedia JRun 3.1/UNIX and Linux systems.
http://download.macromedia.com/pub/security/jrun/31/unix/jrun-31-unix- upgrade-us_49297.sh -
Macromedia jrun-31-win-upgrade-en_49297.exe
Patch for Macromedia JRun 3.1/Windows systems.
http://download.macromedia.com/pub/security/jrun/31/intel-win/jrun-31- win-upgrade-en_49297.exe
Macromedia JRun 4.0
-
Macromedia MPSB02-06_jrun4-patch.zip
Patch for Macromedia JRun 4.0/UNIX and Linux systems.
http://download.macromedia.com/pub/security/jrun/40/MPSB02-06_jrun4-pa tch.zip -
Macromedia MPSB02-06_jrun4-patch.zip
Patch for Macromedia JRun 4.0/Windows systems.
http://download.macromedia.com/pub/security/jrun/40/MPSB02-06_jrun4-pa tch.zip
References
Multiple Vendor WEB-INF Directory Contents Disclosure Vulnerability
References:
References:
- HP IT Resource Center (for US, Canada, Asia-Pacific, & Latin-America) (HP IT Resource Center)
- jo! Homepage (jo!)
- MPSB02-06 - Cumulative Security Patch available for JRun 3.0, 3.1 and 4.0. (Macromedia)
- Oracle 9i Application Server (Oracle)
- Oracle Security Alert #47 version 5 (Oracle)
- Orion Application Server Homepage (Orion*)
- Pramati Homepage (Pramati)
- Sybase Homepage (Sybase)