APP: Oracle HTTP Server Proxy Bypass

This signature detects attempts to exploit a known vulnerability in the way Oracle HTTP Server (OHS) applies access control policy to local resources. All remote HTTP requests proxied by the Oracle Web Cache can bypass the OHS access restriction. Attackers can remotely obtain protected contents.

Extended Description

Oracle HTTP Server(OHS) of Oracle Application Server is prone to an access restriction bypass vulnerability. It is possible to configure a list of forbidden URIs in OHS. This is accomplished using 'mod_access'. A URI that is listed is not supposed to be accessible to certain clients, depending on the configuration. However, reports indicate that the Oracle Webcache client may be used to access URIs regardless of the restrictions outlined in OHS 'mod_access'.

Affected Products

Oracle oracle10g_application_server

Short Name
APP:ORACLE:OHS-PROXY-BYPASS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Bypass CVE-2005-1383 HTTP Oracle Proxy Server bid:13418
Release Date
05/04/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3726
False Positive
Unknown
Vendors

Oracle

CVSS Score

7.5

Found a potential security threat?