|
Oracle 9iAS Apache PL/SQL Module Denial of Service Vulnerability
The Oracle 9iAS web service is powered by the Apache webserver. Included is an Apache module for PL/SQL support. If a request is made to the pls module with a HTTP client authorization header set, and with no auth type defined, the server will suffer an access violation error. A restart is required in order to regain normal functionality. It has been reported that this is not the result of a buffer overflow, and it is not believed to be exploitable to execute code. |
|
|
Privacy Statement |