Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle Webserver setuid root配置文件权限许可和访问控制漏洞
Vulnerability Description
Oracle Webserver 2.1以及更早的版本运行的setuid root,其配置文件归oracle账户所有,任意拥有oracle账户访问权限的本地或远程攻击者可以利用该漏洞。通过修改配置文件获取权限或修改任意文件。
CVSS Information
N/A
Vulnerability Type
N/A