Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle9iAS Web Cache权限提升漏洞
Vulnerability Description
Oracle9iAS Web Cache是一款Oracle 9iAS应用服务程序的WEB缓冲解决方案,提供快速显示动态WEB内容的功能。 Oracle9iAS Web Cache存在设计错误,可以导致本地用户利用此漏洞提升权限来读取受限文件内容。 非特权用户可以通过调用$ORACLE_HOME/webcache/bin/webcached文件来启动Oracle9iAS Web缓冲服务,此文件是setuid oracle属性文件,用户可以指定环境变量和配置文件来导致本地文件被覆盖和以'oracle'用户权限
CVSS Information
N/A
Vulnerability Type
N/A