Categorie: Vulnerability Posted: 2004-02-24 by ReCall Views: 378 Source: Click here
Current Rating: Not rated
Details
Description: Some vulnerabilities were reported in the Oracle Application Server. A remote user may be able to access potentially sensitive services.
It is reported that in the default configuration of the Oracle Application Server 9iAS, a number of services (including Dynamic Monitoring Services) are made accessible to remote users. A remote user can reportedly access the Dynamic Monitoring Services to monitor system information.
Impact: A remote user can access services to obtain potentially sensitive information.
Solution: The vendor has reportedly issued a fix, as described in Oracle Security Alert #28, available at: