Oracle.Application.Server.OracleJSP.Information.Disclosure

description-logoDescription

This indicates an attack attempt to exploit an Information Disclosure vulnerability in Oracle Application Server.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. As a result, a remote attacker can gain unauthorized access to sensitive information by making a direct request to globals.jsa.

affected-products-logoAffected Products

Oracle9i Application Server Web Cache 2.0.x

Impact logoImpact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

recomended-action-logoRecommended Actions

Refer to the vendor's website for suggested workaround.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2024-07-16 28.827
Modified
Name:Oracle9i.
Application.
Server.
OracleJSP.
Information.
Disclosure:Oracle.
Application.
Server.
OracleJSP.
Information.
Disclosure
2019-11-22 15.729
Modified
Name:Oracle.
9IAS.
OracleJSP.
Information.
Disclosure:Oracle9i.
Application.
Server.
OracleJSP.
Information.
Disclosure