vendor:
Oracle9iAS Web Cache
by:
andreas@defcom.com
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Oracle9iAS Web Cache
Affected Version From: 2.0.0.1.0
Affected Version To: 2.0.0.1.0
Patch Exists: YES
Related CWE: CVE-2001-0156
CPE: oracle:web_cache:2.0.0.1.0
Platforms Tested:
2001
Buffer Overflow in Oracle9iAS Web Cache
A buffer overflow condition can be triggered in Oracle 9iAS Web Cache 2.0.0.1.0 by submitting a malicious URL. This overflow can lead to either the process exiting, the process hanging, or the injection of malicious code. This occurs on all four services provided by Web Cache.
Mitigation:
This vulnerability has been addressed in Oracle 91AS Web Cache 2.0.0.2.0. It is recommended to update to the latest version. Versions for Microsoft Windows NT are still vulnerable.