9 lines
No EOL
654 B
Text
9 lines
No EOL
654 B
Text
source: https://www.securityfocus.com/bid/29119/info
|
|
|
|
Oracle Application Server Portal is prone to a authentication-bypass vulnerability because the application fails to properly restrict access to certain resources.
|
|
|
|
An attacker can exploit this vulnerability to bypass certain security restrictions and gain access to potentially sensitive contents of the portal.
|
|
|
|
Oracle Application Server Portal 10g is vulnerable to this issue; other versions may also be affected.
|
|
|
|
Visiting the 'http://www.example.com/portal/%0A' site will create a cookie sufficient to trigger the issue and access 'http://www.example.com/dav_portal/porta/' without authorization. |