Oracle Application Server Oracle Containers for J2EE Directory Traversal Vulnerability
Publish Date: 21 juillet 2015
Gravité: : Medium
Date du conseil: 21 juillet 2015
Description
Oracle Containers for J2EE is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
This issue is associated with Oracle security bug ID 7391479.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
This issue affects Oracle Application Server 10g 10.1.3.1.0; other versions may also be affected.
Information Exposure Rating:
Apply associated Trend Micro DPI Rules.
Solutions
Trend Micro Deep Security DPI Rule Number: 1000128
Trend Micro Deep Security DPI Rule Name: 1000128 - HTTP Protocol Decoding
Affected software and version:
- Oracle Oracle10g Application Server 10.1.3 .1.0