Total vulnerabilities in the database
Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
Software | From | Fixed in |
---|---|---|
oracle / oracle9i | 9.0.1 | 9.0.1.x |
oracle / application_server_web_cache | 2.0.0.2 | 2.0.0.2.x |
oracle / oracle9i | 9.0 | 9.0.x |
oracle / application_server_web_cache | 2.0.0.1 | 2.0.0.1.x |
oracle / application_server_web_cache | 2.0.0.0 | 2.0.0.0.x |
oracle / application_server | 1.0.2 | 1.0.2.x |
oracle / application_server_web_cache | 2.0.0.3 | 2.0.0.3.x |