SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#476619

Oracle 9iAS default configuration allows arbitrary users to view sensitive configuration files

Overview

It is possible to read the "XSQLConfig.xml" and "soapConfig.xml" configuration files from an Oracle 9i Application Server under the default installation without any authorization. This can lead to an intruder gaining access to sensitive information about the server and potentially compromising it.

I. Description

The XSQL configuration and SOAP configuration files contain sensitive information such as the database server host name, user ID's and passwords. Since these files are not protected by default, any user can access it directly through a virtual directory and view the contents.

II. Impact

An intruder can gain sensitive information about the configuration of the server. This information can be used to compromise the server.

III. Solution

Apply the appropriate permissions to these files, please see Oracle's Security Alert on this issue.

Apply the appropriate permissions to the "XSQLConfig.xml" and "soapConfig.xml" configuration files.

Systems Affected

VendorStatusDate Updated
OracleVulnerable27-Feb-2002

References


http://www.nextgenss.com/papers/hpoas.pdf

Credit

Our thanks to David Litchfield of NGSSoftware, who reported on this vulnerability.

This document was written by Jason Rafail and is based on the report by David Litchfield.

Other Information

Date Public02/06/2002
Date First Published03/06/2002 09:17:03 AM
Date Last Updated03/06/2002
CERT Advisory 
CVE-ID(s) 
NVD-ID(s) 
US-CERT Technical Alerts 
Metric42.19
Document Revision8

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2002 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader