Описание
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
Ссылки
- PatchThird Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
- ExploitPatchVendor Advisory
- PatchThird Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:*
EPSS
Процентиль: 89%
0.04432
Низкий
7.5 High
CVSS2
Дефекты
CWE-264
Связанные уязвимости
github
больше 3 лет назад
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
EPSS
Процентиль: 89%
0.04432
Низкий
7.5 High
CVSS2
Дефекты
CWE-264