PT-2008-4049 · Oracle · Oracle Application Server+1
Joxean Koret
·
Publicado
2008-07-15
·
Atualizado
2017-09-29
·
CVE-2008-2595
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Application Server versions 9.0.4.3, 10.1.2.3, 10.1.4.2
Description
The issue concerns an unspecified vulnerability in the Oracle Internet Directory component. It is claimed by researchers to potentially cause a denial of service (crash) via a malformed LDAP request that triggers a NULL pointer dereference, although Oracle has not commented on this. The attack vector is remote.
Recommendations
For versions 9.0.4.3, 10.1.2.3, and 10.1.4.2, consider restricting access to the Oracle Internet Directory component to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Application Server
Oracle Internet Directory