CVE-2007-2120: High severity Oracle Application Server vulnerability
The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Listener via a TNS STOP command in a request that uses the database/TNS alias, aka AS01.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2120?
CVE-2007-2120 has a high severity rating as it allows remote attackers to shut down the Oracle TNS Listener.
How do I fix CVE-2007-2120?
To fix CVE-2007-2120, it is recommended to apply the latest security patches provided by Oracle for the affected versions.
Which versions of Oracle Application Server are affected by CVE-2007-2120?
CVE-2007-2120 affects Oracle Application Server versions 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0.
What can attackers do with CVE-2007-2120?
Attackers can send a TNS STOP command to remotely shut down an Oracle TNS Listener, disrupting service.
Is there a workaround for CVE-2007-2120 if I cannot patch immediately?
A potential workaround for CVE-2007-2120 is to restrict access to the Oracle Discoverer servlet to trusted IPs only.