[NEWS] Oracle Application Server Discloses Full Path for Missing JSP Files

From: support@securiteam.com
Date: 10/07/01


From: support@securiteam.com
To: list@securiteam.com
Subject: [NEWS] Oracle Application Server Discloses Full Path for Missing JSP Files
Message-Id: <20011007064411.2691B138C4@mail.der-keiler.de>
Date: Sun,  7 Oct 2001 08:44:11 +0200 (CEST)

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

When was the last time you checked your server's security?
How about a monthly report?
http://www.AutomatedScanning.com - Know that you're safe.
- - - - - - - - -

  Oracle Application Server Discloses Full Path for Missing JSP Files
------------------------------------------------------------------------

SUMMARY

Oracle Application Server reveals the true path location of JSP files,
when non-existing files are requested.

DETAILS

An information disclosure vulnerability was discovered in Oracle 9i
Application Server. The embedded Apache web service will return the
complete path when a remote user requests a Java server page file that
does not exist.

Example:
http://[targethost]/Content/Home/anyfile.jsp

Results in:

---
Request URI:/Content/Home/Jsp/anyfile.jsp

Exception: javax.serv let.ServletException: java.io.FileNotFoundException: d:\oracle\ias\apache\apache\htdocs\company\content\home\jsp\anyfile.jsp (The system cannot find the file specified) ---

Solution: Follow the solution as it is described in the following article: <http://www.securiteam.com/exploits/5AP0H1F3GG.html> Workaround for the Unintended JSP Execution when using Oracle, Apache and JServ

ADDITIONAL INFORMATION

The information has been provided by <mailto:kkmookhey@yahoo.com> KK Mookhey and <mailto:secalert_us@oracle.com> Oracle Security Alerts.

========================================

This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

==================== ====================

DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • [NEWS] Multiple Vulnerabilities in Oracle Database (Character Conversion, Extproc, Password Disclosu
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Multiple vulnerabilities were discovered in the (Oracle database server ... password is required to exploit this vulnerability. ...
    (Securiteam)
  • Re: How to make your report run faster
    ... I've done no work with Oracle as the Server DB, ... > if they click the listbox then "Preview report" button is enabled. ... > -I was try to make the old queries for subreport, ...
    (microsoft.public.access.reports)
  • Re: I cant find a SETUP.EXE in the SQL Plus Client ??
    ... someone else's server for testing some SELECT statements I'm ... free client because I don't own the Oracle license. ... SQL statements. ... There is no documentation with that download. ...
    (comp.databases.oracle.tools)
  • RE: sunmanagers Digest, Vol 44, Issue 20
    ... diagnostics from the front-panel. ... Any ideas on what the problem may be or how to get this server powered ... The cluster itself is working, but I'm unable to shut down the nodes. ... Oracle uses shared memory for the communication between the client ...
    (SunManagers)
  • Re: I cant find a SETUP.EXE in the SQL Plus Client ??
    ... someone else's server for testing some SELECT statements I'm writing for them. ... How do I get a free Oracle client installed, if possible, so I can test some SQL statements. ... There is no documentation with that download. ...
    (comp.databases.oracle.tools)