Vulnerability Name: | CVE-2001-1371 (CCN-8449) | ||||||||
Assigned: | 2002-01-10 | ||||||||
Published: | 2002-01-10 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-noinfo CWE-264 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2001-1371 Source: BUGTRAQ Type: UNKNOWN 20020206 Hackproofing Oracle Application Server paper Source: CCN Type: Oracle Security Alert #22 Security Implications of the Oracle9iAS Default SOAP Configuration Source: CONFIRM Type: UNKNOWN http://technet.oracle.com/deploy/security/pdf/ias_soap_alert.pdf Source: CCN Type: CERT Advisory CA-2002-08 Multiple vulnerabilities in Oracle Servers Source: CERT Type: Patch, Third Party Advisory, US Government Resource CA-2002-08 Source: XF Type: UNKNOWN oracle-appserver-soap-components(8449) Source: CCN Type: US-CERT VU#736923 Oracle 9iAS SOAP components allow anonymous users to deploy applications by default Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#736923 Source: CCN Type: NGSSoftware Insight Security Research Paper Hackproofing Oracle Application Server Source: MISC Type: UNKNOWN http://www.nextgenss.com/papers/hpoas.pdf Source: CCN Type: OSVDB ID: 5407 Oracle Application Server Default SOAP Configuration Unauthorized Application Deployment Source: BID Type: Exploit, Patch, Vendor Advisory 4289 Source: CCN Type: BID-4289 Oracle 9iAS SOAP Default Configuration Vulnerability Source: XF Type: UNKNOWN oracle-appserver-soap-components(8449) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |