|
|
|
|
| |
Credit:
The information has been provided by Jason Bowes.
The original article can be found at: http://www.zerodayinitiative.com/advisories/ZDI-11-137/
|
| |
Vulnerable Systems:
Oracle Application Server
Authentication is not required to exploit this vulnerability.
The flaw exists within the Web Administration component which listens by default on TCP port 4848. When handling a malformed GET request to the administrative interface, the application does not properly handle an exception allowing the request to proceed without authentication. A remote attacker can exploit this vulnerability to execute arbitrary code under the context of the application.
Patch Availability:
Oracle has issued an update to correct this vulnerability. More details can be found at:
http://www.oracle.com/technetwork/topics/security/cpuapr2011-301950.html
CVE Information:
CVE-2011-0807
Disclosure Timeline:
2010-09-23 - Vulnerability reported to vendor
2011-04-19 - Coordinated public release of advisory
|
|
|
|
|