PT-2014-1215 · Oracle · Oracle Containers For J2Ee+1

Mikhail Firstov

+1

·

Published

2014-04-15

·

Updated

2014-04-16

·

CVE-2014-0413

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Fusion Middleware version 10.1.3.5
Description The issue is related to HTTP Request Handling in the Oracle Containers for J2EE component. It allows remote attackers to affect integrity. The vulnerability is also described as being related to insufficient checking of values in HTTP headers, which can be exploited by adding special CRLF symbols to the header value, allowing an attacker to form a fake HTTP response and display arbitrary data to the user in the context of the vulnerable application.
Recommendations For Oracle Fusion Middleware version 10.1.3.5, consider restricting access to the HTTP Request Handling component until a patch is available. As a temporary workaround, avoid using HTTP headers that can be manipulated by an attacker. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2014-00388
CVE-2014-0413

Affected Products

Oracle Containers For J2Ee
Oracle Fusion Middleware