CVE-2004-0385
Last modified
CVE-2004-0385 is a vulnerability of currently unknown severity. Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities.". EPSS estimates a 15.50% chance of exploitation in the next 30 days.
Description
Heap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execute arbitrary code via a long HTTP request method header to the Web Cache listener. NOTE: due to the vagueness of the Oracle advisory, it is not clear whether there are additional issues besides this overflow, although the advisory alludes to multiple "vulnerabilities."
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server Web Cache | 9.0.0.4.0 |
| Oracle | Application Server Web Cache | 9.0.2.3.0 |
| Oracle | Application Server Web Cache | 9.0.3.1.0 |
| Oracle | Application Server Web Cache | 9.0.4.0.0 |
| Oracle | E-Business Suite | 11i |
References
- http://otn.oracle.com/deploy/security/pdf/2004alert66.pdfPatch, Vendor Advisory
- http://www.inaccessnetworks.com/ian/services/secadv01.txtVendor Advisory
- http://www.kb.cert.org/vuls/id/413006Patch, Third Party Advisory, US Government Resource
- http://otn.oracle.com/deploy/security/pdf/2004alert66.pdfPatch, Vendor Advisory
- http://www.inaccessnetworks.com/ian/services/secadv01.txtVendor Advisory
- http://www.kb.cert.org/vuls/id/413006Patch, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0385?
How severe is CVE-2004-0385?
How do I fix CVE-2004-0385?
Are you affected by CVE-2004-0385?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
