SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#413006

Oracle Application Server Web Cache contains heap overflow vulnerability

Overview

Oracle Application Server Web Cache contains a heap overflow vulnerability in the handling of client requests that could result in arbitrary code execution.

I. Description

The Oracle Web Cache acts as a reverse proxy, caching static and dynamic content generated from Oracle Application web servers. There is a heap overflow vulnerability in the way Oracle Web Cache processes HTTP requests. By supplying an overly long HTTP Request Method header, an attacker could execute arbitrary code with privileges of the vulnerable process.

According to Oracle:

    Web Cache must be running and configured to listen on the Oracle Application Server Web Cache listener port for any client request, regardless of the type of origin Web server (for example, Oracle HTTP Server, Apache or other web servers). If the client request is sent directly to origin Web server (i.e. Oracle HTTP Server, Apache or others), bypassing Web Cache, these vulnerabilities cannot be exploited.

The following products are affected:
  • Oracle Application Server Web Cache 10g (9.0.4.0.0)
  • Oracle9iAS Web Cache 9.0.3.1.0
  • Oracle9iAS Web Cache 9.0.2.3.0
  • Oracle9iAS Web Cache 2.0.0.4.0
  • E-Business Suite 11i configured to use Oracle iStore 11i (11i.IBE.O and later) with Oracle Web Cache 9.0.2.2
  • E-Business Suite 11i Early Adopter customers implementing MetaLink note 233436.1 should apply patches for Oracle Application Server 10g (9.0.4.0.0).

II. Impact

A remote, unauthenticated attacker could execute arbitrary code with privileges of the vulnerable process.

III. Solution

Apply Patch

Oracle has published Oracle Security Alert #66 regarding this issue. For further information, please refer to MetaLink Document ID 265310.1 (login required).

Systems Affected

VendorStatusDate NotifiedDate Updated
Oracle CorporationVulnerable22-Mar-2004

References


http://www.inaccessnetworks.com/ian/services/secadv01.txt
http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf
http://otn.oracle.com/deploy/security/pdf/oracle_severity_ratings.pdf
http://otn.oracle.com/products/ias/web_cache/index.html
http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=265310.1
http://secunia.com/advisories/11118/
http://www.ietf.org/rfc/rfc2616.txt

Credit

Thanks to Ioannis Migadakis of InAccess Networks for reporting this vulnerability.

This document was written by Damon Morda.

Other Information

Date Public:2004-03-15
Date First Published:2004-03-22
Date Last Updated:2004-04-20
CERT Advisory: 
CVE-ID(s):CAN-2004-0385
NVD-ID(s):CAN-2004-0385
US-CERT Technical Alerts: 
Metric:20.32
Document Revision:19

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader