Vulnerability Name: | CCN-21379 | ||||||
Published: | 2005-07-12 | ||||||
Updated: | 2005-07-12 | ||||||
Summary: | Oracle HTTP Server is vulnerable to a denial of service caused by insecure permissions in MOD_ORADAV. A remote attacker could access /DAV_PUBLIC within Mod_Oradav and exhaust all available resources. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||
Vulnerability Consequences: | Denial of Service | ||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Jul 15 2005 - 02:00:57 CDT Silently fixed security bugs in Oracle Critical Patch Update July 2005 Source: CCN Type: Oracle Critical Patch Update Advisory dated July 2005 Oracle Critical Patch Update - July 2005 Source: CCN Type: BID-14274 Oracle9i Application Server MOD_ORADAV Access Control Vulnerability Source: XF Type: UNKNOWN ohs-modoradav-dos(21379) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |