The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Listener via a TNS STOP command in a request that uses the database/TNS alias, aka AS01.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.us-cert.gov/cas/techalerts/TA07-108A.html | third party advisory us government resource |
http://www.red-database-security.com/advisory/oracle_discoverer_servlet.html | |
http://www.oracle.com/technetwork/topics/security/cpuapr2007-090632.html | |
http://www.securityfocus.com/bid/23532 | vdb entry |
http://www.securitytracker.com/id?1017927 | vdb entry |
http://www.securityfocus.com/archive/1/466329/100/200/threaded | vendor advisory |
http://www.red-database-security.com/advisory/oracle_cpu_apr_2007.html | |
http://www.securityfocus.com/archive/1/466160/100/0/threaded | mailing list |
http://www.vupen.com/english/advisories/2007/1426 | vdb entry vendor advisory |