HTTP: Oracle Configuration Disclosure Anonymous Access

This signature detects attemps to access configuration files. These files contain sensitive information about Oracle services configuration.

Extended Description

Oracle 9iAS installations include the Apache web server and several Apache services which are installed by default. On default installations of Oracle 9iAS, unauthenticated remote users can view sensitive services, including Dynamic Monitoring Services.

Affected Products

Oracle oracle9i_application_server

Short Name
HTTP:ORACLE:CONF-ACCESS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Access Anonymous CVE-2002-0563 Configuration Disclosure Oracle bid:4293
Release Date
10/20/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Oracle

CVSS Score

5.0

Found a potential security threat?