CVE-2004-1877: Low severity Oracle HTTP Server vulnerability
The psubmiturl value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1877?
CVE-2004-1877 is classified as a medium severity vulnerability due to its potential for user credential exposure.
How do I fix CVE-2004-1877?
To fix CVE-2004-1877, apply the latest patches provided by Oracle for the affected versions of Oracle 9i Application Server.
What kind of attack can exploit CVE-2004-1877?
CVE-2004-1877 can be exploited through a spoofing attack targeting the login page, leading to credential theft.
Which software versions are affected by CVE-2004-1877?
CVE-2004-1877 affects various versions of Oracle Java System Application Server, including 1.0.2, 9.0.2, and others listed in the vulnerability details.
Is user education necessary to mitigate CVE-2004-1877?
Yes, user education about recognizing phishing attempts and verifying URL authenticity can help mitigate the risks associated with CVE-2004-1877.