|
|
Vulnerability Assessment & Network Security Forums |
|||||||||
|
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Databases >> Oracle 9iAS access to SOAP documentation Vulnerability Assessment Details
|
Oracle 9iAS access to SOAP documentation |
||
|
Tries to retrieve Oracle9iAS SOAP documentation Detailed Explanation for this Vulnerability Assessment In a default installation of Oracle 9iAS, it is possible to access SOAP documentation. These files might be useful for a possible hacker to acertain what application server is being used. Solution: Remove the 'soapdocs' alias from the Oracle 9iAS http.conf: Alias /soapdocs/ $ORACLE_HOME/soap/docs/ Note that the default installation of Oracle 9iAS 1.0.2.2 does not seem to suffer this issue. More information: http://otn.oracle.com/deploy/security/pdf/ias_soap_alert.pdf http://www.cert.org/advisories/CA-2002-08.html Also read: Hackproofing Oracle Application Server from NGSSoftware: available at http://www.nextgenss.com/papers/hpoas.pdf Network Security Threat Level: Low Networks Security ID: Vulnerability Assessment Copyright: This script is Copyright (C) 2003 Javier Fernandez-Sanguino |
||
|
Cables, Connectors |
|
||
|
No Discussions have been posted on this vulnerability. |