CVE-2001-1371: High severity Oracle Application Server vulnerability
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1371?
CVE-2001-1371 is considered to have a high severity due to the potential for unauthorized application deployment.
How do I fix CVE-2001-1371?
To fix CVE-2001-1371, it is recommended to disable SOAP services or configure access controls to restrict anonymous user access.
What platforms are affected by CVE-2001-1371?
CVE-2001-1371 specifically affects Oracle Application Server version 1.0.2.
Can CVE-2001-1371 be exploited remotely?
Yes, CVE-2001-1371 can be exploited remotely by anonymous users to deploy applications due to the default configuration.
Is there a patch available for CVE-2001-1371?
There is no specific patch available for CVE-2001-1371, but changing the default configuration is recommended to mitigate the risk.