First published: Mon Mar 12 2001(Updated: )
Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =8.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0126 is considered a critical vulnerability due to the potential for remote code execution.
To fix CVE-2001-0126, upgrade to a later version of the Oracle XSQL servlet that does not contain this vulnerability.
CVE-2001-0126 affects users of Oracle XSQL servlet version 1.0.3.0 and earlier, particularly those running Oracle 8i 8.1.7.
CVE-2001-0126 can be exploited through an attacker manipulating the xml-stylesheet parameter to execute arbitrary Java code remotely.
There are no documented workarounds for CVE-2001-0126; upgrading to a secure version is the recommended approach.