|
Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability
The Oracle 9iAS web service is powered by the Apache webserver. Included is an Apache module for PL/SQL support. Administrative web pages associated with this server allow a web user to modify Database Access Descriptors and cache settings. By default, no authentication is required to access these administrative pages. As a result, any attacker able to access the page may perform these administrative functions. The ability to modify DAD settings may allow an attacker to access or modify PL/SQL applications, or deny service to legitimate users. |
|
|
Privacy Statement |