Oracle Application Server Oracle Containers for J2EE Directory Traversal Vulnerability
2015年7月21日
危険度: 中
情報公開日: 7 21, 2015
概要
Oracle Containers for J2EE is prone to a directory-traversal vulnerability because the application fails to sufficiently sanitize user-supplied input.
This issue is associated with Oracle security bug ID 7391479.
Exploiting this issue will allow an attacker to view arbitrary local files within the context of the webserver. Information harvested may aid in launching further attacks.
This issue affects Oracle Application Server 10g 10.1.3.1.0; other versions may also be affected.
トレンドマイクロの対策
Apply associated Trend Micro DPI Rules.
対応方法
Trend Micro Deep Security DPI Rule Number: 1000128
Trend Micro Deep Security DPI Rule Name: 1000128 - HTTP Protocol Decoding
影響を受けるソフトウェア
- Oracle Oracle10g Application Server 10.1.3 .1.0