Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Oracle 9iAS Apache PL/SQL Module Web Administration Access Vulnerability

The Oracle 9iAS web service is powered by the Apache webserver. Included is an Apache module for PL/SQL support. Administrative web pages associated with this server allow a web user to modify Database Access Descriptors and cache settings.

By default, no authentication is required to access these administrative pages. As a result, any attacker able to access the page may perform these administrative functions. The ability to modify DAD settings may allow an attacker to access or modify PL/SQL applications, or deny service to legitimate users.







 

Privacy Statement
Copyright 2008, SecurityFocus