CVE-2008-2138: Medium severity oracle application server portal vulnerability
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /davportal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-2138?
CVE-2008-2138 is classified as a medium severity vulnerability due to its potential for unauthorized access.
How do I fix CVE-2008-2138?
To fix CVE-2008-2138, it is recommended to apply the latest patches provided by Oracle for the Application Server Portal 10g.
What systems are affected by CVE-2008-2138?
CVE-2008-2138 specifically affects Oracle Application Server Portal version 10g.
What type of attack does CVE-2008-2138 enable?
CVE-2008-2138 enables remote attackers to bypass access restrictions and read unauthorized content.
Is CVE-2008-2138 a widespread vulnerability?
CVE-2008-2138 is a significant vulnerability, but its impact is limited to environments using Oracle Application Server Portal 10g.