Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Oracle 9i Default Configuration File Information Disclosure Vulnerability

Oracle 9iAS includes two important configuration files called "XSQLConfig.xml" and "soapConfig.xml". The configuration files contain sensitive information, such as database usernames and passwords.

Both of these files are accessible to remote clients without any authentication. It is possible for malicious users to access and read the files through a virtual directory.

Possibly sensitive information disclosed to attackers may assist in further attacks.







 

Privacy Statement
Copyright 2008, SecurityFocus