CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Vulnerabilities: Oracle warns of three new flaws image
Web Servers
Oracle warns of three new flaws
By Robert Lemos
CNET News.com
July 24, 2003, 2:59 PM PT
URL: http://zdnet.com.com/2100-1105-5053714.html
Database maker Oracle warned customers on Wednesday of three new flaws in its products and reiterated its warning to businesses of a fourth flaw that uses the company's application server.

The two most serious vulnerabilities were in the firm's E-Business Suite, Oracle's set of server applications for managing everything from accounting to Intranets. Both were given the highest of three threat ratings assigned by Oracle to its products' vulnerabilities.


Our rating system is based upon likelihood of exploitation and risk of damage if the issue were exploited, said John Heimann, director of security product management for Oracle. Either of these issues is exploitable and could result in damage if exploited.

Oracle has issued advisories and patches on all four vulnerabilities.

The first E-Business Suite vulnerability, caused by a set of unsecured Java server pages, could allow any user to view the product's configuration and host-system information. The second flaw, a buffer overflow, could lead a component of the suite to crash and potentially allow an attacker to run code on the system.

The flaw in the company's database server could allow an attacker to execute code against the system--but only if the person already has database-administrator rights to the system. The main concern with this type of an attack is that a company insider could gain a higher level of privilege on the server.

Oracle also reiterated a warning about several flaws in the application server that could allow people to read files or to look at the source code of Java server pages.

http://zdnet.com.com/2100-1105_2-5053714.html
http://otn.oracle.com/deploy/security/alerts.htm
Posted on Thursday, 24 July 2003 @ 21:25:16 UTC by phoenix22 (1048 reads)
[ Trackback ]
image

"Vulnerabilities: Oracle warns of three new flaws" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· News.com
· HotScripts
· W3 Consortium
· Oracle
· C|Net News
· ZDNet News
· More about Web Servers
· News by phoenix22


Most read story about Web Servers:
Guide to Anonymous Proxy Surfing

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer