This application requires Javascript for optimal performance.

Oracle.9i.Application.Server.Web.Cache.Administration.DoS

Alias(es)

Oracle9i.Application.Server.Web.Cache.Administration.DoS.B, Oracle9i.Application.Server.Web.Cache.Administration.DoS.A

Release Date

Aug 23, 2005

Severity

medium

Impact

Denial of Service.

Description

This indicates a Denial of Service attack against the Oracle9i Application Server Web Administration Module.

Oracle 9i Application Server has a web component that allows administrators to access it remotely. A malicious user can craft a request which, when sent to the Web Administration Module, will cause it to crash.

Affected Products

Oracle Oracle9i Application Server 9.0.2.

Recommended Actions

Use firewall techniques to restrict access to the Web Cache administration port.

Use the Secure Subnets feature of the Web Cache Manager tool to provide access only to administrators connecting from a list of permitted IP addresses or subnets.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2002-0386

Reference/s

http://www.securityfocus.com/bid/5902 (BugTraq)

Reference: VID-10824