Oracle9i.Default.Configuration.File.Information.Disclosure

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure vulnerability in Oracle 9i Application Server.
The vulnerability is due to insufficient input validation in the application allowing users to access the the XSQLConfig.xml and soapConfig.xml configuration files. As a result, a remote attacker can gain unauthorized access to sensitive information.

affected-products-logoAffected Products

Oracle Oracle9i Standard Edition 9.0.1
Oracle Oracle9i Standard Edition 9.0
Oracle Oracle9i Application Server 1.0.2
Oracle Oracle8i Standard Edition 8.1.7 .1
Oracle Oracle8i Standard Edition 8.1.7

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's website for suggested workaround.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)