Vulnerability Name:

CVE-2004-0385 (CCN-15463)

Assigned:2004-03-12
Published:2004-03-12
Updated:2017-07-11
Summary:Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener.
Note: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: VULNWATCH
Type: UNKNOWN
20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache

Source: CCN
Type: VulnWatch Mailing List, Thu Apr 08 2004 - 07:48:43 CDT
Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache

Source: MITRE
Type: CNA
CVE-2004-0385

Source: CCN
Type: SANS Handler's Diary March 13th 2004
Oracle Application Server Web Cache Vulnerabilities; Port 65506

Source: BUGTRAQ
Type: UNKNOWN
20040316 new security alert #66 issued in Oracle web cache

Source: BUGTRAQ
Type: UNKNOWN
20040408 Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache

Source: CCN
Type: Oracle Security Alert #66
Vulnerabilities in Oracle Application Server Web Cache

Source: CONFIRM
Type: Patch, Vendor Advisory
http://otn.oracle.com/deploy/security/pdf/2004alert66.pdf

Source: CCN
Type: SA11118
Oracle Web Cache HTTP Request Method Heap Overflow Vulnerability

Source: SECUNIA
Type: UNKNOWN
11118

Source: MISC
Type: Vendor Advisory
http://www.inaccessnetworks.com/ian/services/secadv01.txt

Source: CCN
Type: US-CERT VU#413006
Oracle Application Server Web Cache contains heap overflow vulnerability

Source: CERT-VN
Type: Patch, Third Party Advisory, US Government Resource
VU#413006

Source: OSVDB
Type: UNKNOWN
4249

Source: CCN
Type: OSVDB ID: 15438
Oracle Web Cache HTTP Request Method Header Overflow

Source: CCN
Type: OSVDB ID: 42489
Flyspray Username Error Message Information Disclosure

Source: CCN
Type: OSVDB ID: 4249
Flyspray Username Error Message Information Disclosure

Source: BID
Type: UNKNOWN
9868

Source: CCN
Type: BID-9868
Oracle Application Server Web Cache HTTP Request Method Heap Overrun Vulnerability

Source: XF
Type: UNKNOWN
oracle-webcache-http-bo(15463)

Source: XF
Type: UNKNOWN
oracle-web-cache-vulnerabilities(15463)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:application_server_web_cache:9.0.0.4.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server_web_cache:9.0.2.3.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server_web_cache:9.0.3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server_web_cache:9.0.4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:e-business_suite:11i:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:oracle:application_server_web_cache:9.0.4.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server_web_cache:9.0.3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:application_server_web_cache:9.0.2.3.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    oracle application server web cache 9.0.0.4.0
    oracle application server web cache 9.0.2.3.0
    oracle application server web cache 9.0.3.1.0
    oracle application server web cache 9.0.4.0.0
    oracle e-business suite 11i
    oracle application server web cache 9.0.4.0.0
    oracle application server web cache 9.0.3.1.0
    oracle application server web cache 9.0.2.3.0