Oracle9i.Application.Server.OracleJSP.Information.Disclosure
Description
This indicates an attack attempt to exploit an Information Disclosure vulnerability in Oracle 9i Application Server.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. As a result, a remote attacker can gain unauthorized access to sensitive information by making a direct request to globals.jsa.
Affected Products
Oracle Oracle9i Application Server Web Cache 2.0.x
Impact
Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.
Recommended Actions
Refer to the vendor's website for suggested workaround.
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2019-11-22 | 15.729 | Name:Oracle. 9IAS. OracleJSP. Information. Disclosure:Oracle9i. Application. Server. OracleJSP. Information. Disclosure |