Oracle Application Server Web Cache HTTP Request Method Heap Overrun Vulnerability
Publish Date: 21 de §Ú§ð§Ý§ñ de 2015
Severity: : Critical
CVE Kennungen: : CVE-2004-385
Advisory Date: 21 de §Ú§ð§Ý§ñ de 2015
DESCRIPTION
Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."
INFORMATION EXPOSURE
Apply associated live casino online DPI Rules.
SOLUTION
live casino online Deep Security DPI Rule Number: 1000552
live casino online Deep Security DPI Rule Name: 1000552 - Generic Cross Site Scripting(XSS) Prevention
AFFECTED SOFTWARE AND VERSION:
- Oracle Application Server