PT-2006-6073 · Apache+1 · Mod Rewrite Module+3

Publicado

2006-10-18

·

Atualizado

2018-10-17

·

CVE-2006-5353

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Application Server versions 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, 10.1.3.0.0 Oracle Collaboration Suite versions 9.0.4.2, 10.1.2
Description The issue is related to the Mod rewrite Module in the Oracle HTTP Server component and has unknown impact with remote attack vectors.
Recommendations For Oracle Application Server versions 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, 10.1.3.0.0, consider disabling the Mod rewrite Module as a temporary workaround until a patch is available. For Oracle Collaboration Suite versions 9.0.4.2, 10.1.2, restrict access to the Mod rewrite Module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5353

Produtos afetados

Mod Rewrite Module
Oracle Application Server
Oracle Collaboration Suite
Oracle Http Server