![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
CVE ID: | CVE-2002-0568 |
Description: | Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory. |
Test IDs: | 1.3.6.1.4.1.25623.1.0.10855 1.3.6.1.4.1.25623.1.0.11224 |
Cross References: |
Common Vulnerability Exposure (CVE) ID: CVE-2002-0568 BugTraq ID: 4290 http://www.securityfocus.com/bid/4290 Bugtraq: 20020206 Hackproofing Oracle Application Server paper (Google Search) http://marc.info/?l=bugtraq&m=101301813117562&w=2 Cert/CC Advisory: CA-2002-08 http://www.cert.org/advisories/CA-2002-08.html CERT/CC vulnerability note: VU#476619 http://www.kb.cert.org/vuls/id/476619 http://www.nextgenss.com/papers/hpoas.pdf |