Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-59f3-q6cq-qcpj

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

EPSS

Процентиль: 75%
0.00935
Низкий

Связанные уязвимости

nvd
почти 28 лет назад

Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

EPSS

Процентиль: 75%
0.00935
Низкий