First published: Mon May 02 2005(Updated: )
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server | =10.1.0.3 | |
Oracle Application Server | =10.1.0.2 | |
Oracle Application Server | =10.1.0.3.1 | |
Oracle Application Server | =10.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1383 has a medium severity level, indicating a moderate risk to affected systems.
To fix CVE-2005-1383, ensure that the UseWebcacheIP option is enabled in the Oracle Application Server configuration.
CVE-2005-1383 affects Oracle Application Server versions 10.1.0.2, 10.1.0.3, 10.1.0.3.1, and 10.1.2.
CVE-2005-1383 allows attackers to bypass HTTP Server mod_access restrictions through specific TCP requests.
Yes, CVE-2005-1383 is known to have public exploit code that can be used to demonstrate the vulnerability.