First published: Wed Feb 06 2002(Updated: )
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1371 is considered to have a high severity due to the potential for unauthorized application deployment.
To fix CVE-2001-1371, it is recommended to disable SOAP services or configure access controls to restrict anonymous user access.
CVE-2001-1371 specifically affects Oracle Application Server version 1.0.2.
Yes, CVE-2001-1371 can be exploited remotely by anonymous users to deploy applications due to the default configuration.
There is no specific patch available for CVE-2001-1371, but changing the default configuration is recommended to mitigate the risk.