Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
From: Oracle Security Alerts (secalert_usORACLE.COM)
Date: Mon Feb 12 2001 - 16:08:31 CST
Patch for Potential Vulnerability in the execution of JSPs outside
Description of the problem
A potential security vulnerability has been discovered in Oracle JSP
releases 1.0.x through 1.1.1 (in Apache/Jserv). This vulnerability
permits access to and execution of unintended JSP files outside the
doc_root in Apache/Jserv. For example, accessing
http://HOST/a.jsp//..//..//..//..//..//../b.jsp will execute b.jsp
outside the doc_root instead of a.jsp if there is a b.jsp file in the
Oracle8i Release 8.1.7, iAS Release 1.0.2
Oracle JSP, Apache/JServ Releases 1.0.x - 1.1.1
Likelihood of Occurrence
Whenever //.. is present in the URI while using Apache/JServ.
Upgrade to OJSP Release 220.127.116.11.0 which is available on Oracle
Technology Network's OJSP web site.
Oracle Corporation wishes to thank Georgi Guninski for discovering this
vulnerability and promptly bringing it to Oracle's attention.