Vulnerabilities > CVE-2004-0385 - Unspecified vulnerability in Oracle Application Server web Cache and E-Business Suite
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 5 |
Nessus
NASL family | Databases |
NASL id | ORACLE_WEB_CACHE_MULTIPLE_VULNS.NASL |
description | The remote host is running a version of Oracle Application Server Web Cache version 9.0.4.0 or older. The installed version is affected by a heap overflow vulnerability. Provided Web Cache is running and configured to listen on Oracle Application Server Web Cache listener port and accept requests from any client it may be possible for an attacker to execute arbitrary code on the remote system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 12126 |
published | 2004-04-04 |
reporter | This script is Copyright (C) 2004-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/12126 |
title | Oracle Application Server Web Cache <= 9.0.4.0 Multiple Vulnerabilities |
code |
|
References
- http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0078.html
- http://marc.info/?l=bugtraq&m=107945649127635&w=2
- http://marc.info/?l=bugtraq&m=108144419001770&w=2
- http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf
- http://secunia.com/advisories/11118
- http://www.inaccessnetworks.com/ian/services/secadv01.txt
- http://www.kb.cert.org/vuls/id/413006
- http://www.osvdb.org/4249
- http://www.securityfocus.com/bid/9868
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15463