This site is deprecated. Please
CLICK HERE for latest updates
Short Name |
DB:ORACLE:AS-EMCHARTBEAN-TRAV
|
Severity |
Minor
|
Recommended |
No
|
Category |
DB
|
Keywords |
Oracle Application Server Directory Traversal Attack
|
Release Date |
2007/02/14
|
Update Number |
1213
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+
|
DB: Oracle Application Server Directory Traversal Attack
This signature detects attempts to exploit a known vulnerability against Oracle Application Server. Attackers can perform a directory traversal attack to access files outside of the Web root directory.
Extended Description
Oracle has released a Critical Patch Update advisory for January 2007 to address these vulnerabilities for supported releases. Earlier unsupported releases are likely to be affected by these issues as well.
The issues identified by the vendor affect all security properties of the Oracle products and present local and remote threats. Various levels of authorization are needed to leverage some of the issues, but other issues do not require any authorization. The most severe of the vulnerabilities could possibly expose affected computers to complete compromise.
Affected Products
- Apple mac_os_x 10.4.10
- Apple mac_os_x 10.4.11
- Apple mac_os_x_server 10.4.10
- Apple mac_os_x_server 10.4.11
- Hp oracle_for_openview 8.1.7
- Hp oracle_for_openview 9.1.01
- Hp oracle_for_openview 9.2
- Hp oracle_for_openview_for_linux_ltu
- Oracle application_server_10g 9.0.4
- Oracle application_server_10g 9.0.4 .1
- Oracle application_server_10g 9.0.4 .2
- Oracle application_server_10g 9.0.4 .3
- Oracle application_server_release_2 10.1.2 .0.0
- Oracle application_server_release_2 10.1.2 .0.1
- Oracle application_server_release_2 10.1.2 .0.2
- Oracle application_server_release_2 9.0.2 .3
- Oracle developer_suite 10.1.2.0.2
- Oracle developer_suite 6i
- Oracle developer_suite 9.0.4 .3
- Oracle e-business_suite 11.0.0
- Oracle e-business_suite_11i 11.5.10
- Oracle e-business_suite_11i 11.5.10 CU2
- Oracle e-business_suite_11i 11.5.7
- Oracle e-business_suite_11i 11.5.8
- Oracle e-business_suite_11i 11.5.9
- Oracle enterprise_manager_grid_control_10g 10.1.0 .3
- Oracle enterprise_manager_grid_control_10g 10.1.0 .4
- Oracle enterprise_manager_grid_control_10g 10.1.0 .5
- Oracle enterprise_manager_grid_control_10g 10.2.0 .1
- Oracle oracle10g_application_server 10.1.2
- Oracle oracle10g_application_server 10.1.2 .0.1
- Oracle oracle10g_application_server 10.1.2 .0.2
- Oracle oracle10g_application_server 10.1.2 .1.0
- Oracle oracle10g_application_server 10.1.2 .2.0
- Oracle oracle10g_application_server 10.1.3 .0.0
- Oracle oracle10g_application_server 10.1.3 .4.0
- Oracle oracle10g_application_server 9.0.4 .1
- Oracle oracle10g_application_server 9.0.4 .2
- Oracle oracle10g_enterprise_edition 10.1.0 .0.2
- Oracle oracle10g_enterprise_edition 10.1.0 .0.3
- Oracle oracle10g_enterprise_edition 10.1.0 .0.3.1
- Oracle oracle10g_enterprise_edition 10.1.0 .0.4
- Oracle oracle10g_enterprise_edition 10.2.0 .1
- Oracle oracle10g_enterprise_edition 10.2.0 .2
- Oracle oracle10g_enterprise_edition 10.2.0 .3
- Oracle oracle10g_personal_edition 10.1.0 .0.2
- Oracle oracle10g_personal_edition 10.1.0 .0.3
- Oracle oracle10g_personal_edition 10.1.0 .0.3.1
- Oracle oracle10g_personal_edition 10.1.0 .0.4
- Oracle oracle10g_personal_edition 10.2.0 .1
- Oracle oracle10g_personal_edition 10.2.0 .2
- Oracle oracle10g_personal_edition 10.2.0 .3
- Oracle oracle10g_standard_edition 10.1.0 .0.2
- Oracle oracle10g_standard_edition 10.1.0 .0.3
- Oracle oracle10g_standard_edition 10.1.0 .0.3.1
- Oracle oracle10g_standard_edition 10.1.0 .0.4
- Oracle oracle10g_standard_edition 10.1.0 .0.5
- Oracle oracle10g_standard_edition 10.1.0 .4.2
- Oracle oracle10g_standard_edition 10.2.0.1
- Oracle oracle10g_standard_edition 10.2.0 .2
- Oracle oracle10g_standard_edition 10.2.0 .3
- Oracle oracle8i_enterprise_edition 8.1.7.4.0
- Oracle oracle8i_standard_edition 8.1.7 .4
- Oracle oracle_9i_application_server_release_1 1.0.2 .2
- Oracle oracle9i_enterprise_edition 9.0.1 .4
- Oracle oracle9i_enterprise_edition 9.0.1 .5
- Oracle oracle9i_enterprise_edition 9.0.1 .5 FIPS
- Oracle oracle9i_enterprise_edition 9.2.0 .0.5
- Oracle oracle9i_enterprise_edition 9.2.0.6.0
- Oracle oracle9i_enterprise_edition 9.2.0.7.0
- Oracle oracle9i_enterprise_edition 9.2.0.8.0
- Oracle oracle9i_personal_edition 9.0.1 .4
- Oracle oracle9i_personal_edition 9.0.1 .5
- Oracle oracle9i_personal_edition 9.0.1 .5 FIPS
- Oracle oracle9i_personal_edition 9.2.0 .0.5
- Oracle oracle9i_personal_edition 9.2.0 .6
- Oracle oracle9i_personal_edition 9.2.0 .7
- Oracle oracle9i_personal_edition 9.2.0 .8
- Oracle oracle9i_standard_edition 9.0.1 .4
- Oracle oracle9i_standard_edition 9.0.1 .5
- Oracle oracle9i_standard_edition 9.0.1 .5 FIPS
- Oracle oracle9i_standard_edition 9.2.0 .0.5
- Oracle oracle9i_standard_edition 9.2.0 .6
- Oracle oracle9i_standard_edition 9.2.0 .7
- Oracle oracle9i_standard_edition 9.2.0.8
- Oracle oracle_identity_management_10g 10.1.4 .0.1
- Oracle peoplesoft_enterprise_peopletools 8.22
- Oracle peoplesoft_enterprise_peopletools 8.47
- Oracle peoplesoft_enterprise_peopletools 8.48
- Red_hat red_hat_network_satellite_server 5.0.0
References