Short Name |
HTTP:ORACLE:SOAP-ACCESS |
|---|---|
Severity |
Low |
Recommended |
No |
Category |
HTTP |
Release Date |
2006/10/20 |
Update Number |
1213 |
Supported Platforms |
di-5.3+ |
This signature detects attempts to exploit a known vulnerability against Oracle Application Server. In its default configuration, attackers can execute arbitrary SOAP applications through the SOAP interface.
Security issues reportedly exist with Oracle's Simple Object Access Protocol (SOAP) implementation. It is possible for remote attackers to deploy and undeploy SOAP providers and services without valid credentials by default. Further compromise may occur if this vulnerability is exploited in conjunction with others.