First published: Wed Apr 18 2007(Updated: )
The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Listener via a TNS STOP command in a request that uses the database/TNS alias, aka AS01.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server | =10.1.2.2 | |
Oracle Application Server | =10.1.2.0.2 | |
Oracle Application Server | =9.0.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2120 has a high severity rating as it allows remote attackers to shut down the Oracle TNS Listener.
To fix CVE-2007-2120, it is recommended to apply the latest security patches provided by Oracle for the affected versions.
CVE-2007-2120 affects Oracle Application Server versions 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0.
Attackers can send a TNS STOP command to remotely shut down an Oracle TNS Listener, disrupting service.
A potential workaround for CVE-2007-2120 is to restrict access to the Oracle Discoverer servlet to trusted IPs only.