Vulnerability Description
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Http Server | <= 2.1 |
References
FAQ
What is CVE-1999-1125?
CVE-1999-1125 is a vulnerability with a CVSS score of 10.0 (HIGH). Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain...
How severe is CVE-1999-1125?
CVE-1999-1125 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-1999-1125?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Http Server.