Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

APP:ORACLE:OHS-PROXY-BYPASS

Severity

Medium

Recommended

No

Recommended Action

Drop

Category

APP

Keywords

Oracle HTTP Server Proxy Bypass

Release Date

2005/05/04

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

APP: Oracle HTTP Server Proxy Bypass


This signature detects attempts to exploit a known vulnerability in the way Oracle HTTP Server (OHS) applies access control policy to local resources. All remote HTTP requests proxied by the Oracle Web Cache can bypass the OHS access restriction. Attackers can remotely obtain protected contents.

Extended Description

Oracle HTTP Server(OHS) of Oracle Application Server is prone to an access restriction bypass vulnerability. It is possible to configure a list of forbidden URIs in OHS. This is accomplished using 'mod_access'. A URI that is listed is not supposed to be accessible to certain clients, depending on the configuration. However, reports indicate that the Oracle Webcache client may be used to access URIs regardless of the restrictions outlined in OHS 'mod_access'.

Affected Products

  • Oracle Oracle10g Application Server 10.1.0 .0.2
  • Oracle Oracle10g Application Server 10.1.0 .0.3
  • Oracle Oracle10g Application Server 10.1.0 .0.3.1
  • Oracle Oracle10g Application Server 10.1.2
  • Oracle Oracle10g Application Server 9.0.4 .0
  • Oracle Oracle10g Application Server 9.0.4 .1
  • Oracle Oracle9i Application Server 1.0.2
  • Oracle Oracle9i Application Server 1.0.2 .1s
  • Oracle Oracle9i Application Server 1.0.2 .2
  • Oracle Oracle9i Application Server 1.0.2 .2.2
  • Oracle Oracle9i Application Server 9.0.2
  • Oracle Oracle9i Application Server 9.0.2 .0.0
  • Oracle Oracle9i Application Server 9.0.2 .0.1
  • Oracle Oracle9i Application Server 9.0.2 .1
  • Oracle Oracle9i Application Server 9.0.2 .2
  • Oracle Oracle9i Application Server 9.0.2 .3
  • Oracle Oracle9i Application Server 9.0.3
  • Oracle Oracle9i Application Server 9.0.3 .1
  • Oracle Oracle9i Application Server 9.2.0 .0.6
  • Oracle Oracle9i Application Server
  • Oracle Oracle HTTP Server 8.1.7
  • Oracle Oracle HTTP Server 9.0.1
  • Oracle Oracle HTTP Server 9.2.0 .0

References

  • BugTraq: 13418
  • CVE: CVE-2005-1383
  • URL: http://www.ipolicynetworks.com/technology/files/Oracle_HTTP_Server_mod_access_Restriction_Bypass.html
  • URL: http://www.sans.org/newsletters/risk/display.php?v=4&i=15

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out