30140Third-party advisory
http://secunia.com/advisories/30140 CVE-2008-2138
Oracle Application Server Portal 10g - Authentication Bypass
Record summary
CVE-2008-2138 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOracle Application Server Portal 10g - Authentication BypassExploitDB exploitby Deniz CevikNot analyzed1 file
References
73867Third-party advisory
http://securityreason.com/securityalert/3867 20080509 Oracle Application Server 10G ORA_DAV Basic Authentication Bypass Vulnerabilitymailing list
http://www.securityfocus.com/archive/1/491865/100/0/threaded 29119vdb entry
http://www.securityfocus.com/bid/29119 1020034vdb entry
http://www.securitytracker.com/id?1020034 oracle-aps-cookie-auth-bypass(42302)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/42302 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2138