Vulnerabilties in FTP and HTTP access to Oracle XML Database 9.2.0.1
| Attack ID: | CPAI-2003-29 | ||||||||||||
| Publish Date: | |||||||||||||
| Category: | Remote code execution | ||||||||||||
| Vulnerable Systems: | Oracle 9i XDB (XML Database) ver 9.2.0.1 | ||||||||||||
| Source: | http://www.blackhat.com/presentations/bh-usa-03/bh-us-03-litchfield-paper.pdf | ||||||||||||
| Description: | Oracle XML Database is vulnerable to 4 different buffer oveflow attacks via its FTP and HTTP access. | ||||||||||||
| Severity: | |||||||||||||
| Succesful exploit may lead to remote code execution. | |||||||||||||
| Details: | The Oracle XML Databse (XDB) is accessible via FTP on port 2100 and HTTP on port 8080. There are 4 different buffer overflows in the FTP and HTTP servers, via:
|
||||||||||||
| Attack Detection: | The FTP 'test' and 'lock' commands will be blocked with log: reason: command: 'test' was blocked |
||||||||||||
| Solution: | Use User-Authentication to authenticate users prior to acessing the Oracle XDB FTP and HTTP servers. This will require authentication prior to accessing the server as well as protect from the 'test' and 'lock' commands vulnerabilities.
|
||||||||||||
| Industry Reference: | |||||||||||||
| Additional Information: | |||||||||||||