Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle 9iAS SOAP默认配置漏洞
Vulnerability Description
Oracle 9iAS是一种大型的关系数据库系统,由Oracle公司开发和维护。 它支持简单对象访问协议(SOAP)协议,它是一种基于XML的协议,Oracle用它来对数据库服务进行Web管理。 Oracle 9iAS 1.0.2.2.1缺省安装并使能了SOAP组件,远程攻击者无须认证即可配置或关闭(deploy/undploy)SOAP的提供者及服务。 与其它漏洞结合,攻击者可能进行更进一步的破坏。
CVSS Information
N/A
Vulnerability Type
N/A