Vulnerability Note VU#413006
Oracle Application Server Web Cache contains heap overflow vulnerability
Overview
Oracle Application Server Web Cache contains a heap overflow vulnerability in the handling of client requests that could result in arbitrary code execution.
Description
The Oracle Web Cache acts as a reverse proxy, caching static and dynamic content generated from Oracle Application web servers. There is a heap overflow vulnerability in the way Oracle Web Cache processes HTTP requests. By supplying an overly long HTTP Request Method header, an attacker could execute arbitrary code with privileges of the vulnerable process. According to Oracle:
The following products are affected:
|
Impact
A remote, unauthenticated attacker could execute arbitrary code with privileges of the vulnerable process. |
Solution
Apply Patch
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Oracle Corporation | Affected | - | 22 Mar 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.inaccessnetworks.com/ian/services/secadv01.txt
- http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf
- http://otn.oracle.com/deploy/security/pdf/oracle_severity_ratings.pdf
- http://otn.oracle.com/products/ias/web_cache/index.html
- http://metalink.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=265310.1
- http://secunia.com/advisories/11118/
- http://www.ietf.org/rfc/rfc2616.txt
Credit
Thanks to Ioannis Migadakis of InAccess Networks for reporting this vulnerability.
This document was written by Damon Morda.
Other Information
- CVE IDs: CAN-2004-0385
- Date Public: 15 Mar 2004
- Date First Published: 22 Mar 2004
- Date Last Updated: 20 Apr 2004
- Severity Metric: 20.32
- Document Revision: 19
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.