Vulnerability Description
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server Portal | 10g |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/30140
- http://securityreason.com/securityalert/3867
- http://www.securityfocus.com/archive/1/491865/100/0/threaded
- http://www.securityfocus.com/bid/29119Exploit
- http://www.securitytracker.com/id?1020034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42302
- http://secunia.com/advisories/30140
- http://securityreason.com/securityalert/3867
- http://www.securityfocus.com/archive/1/491865/100/0/threaded
- http://www.securityfocus.com/bid/29119Exploit
- http://www.securitytracker.com/id?1020034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42302
FAQ
What is CVE-2008-2138?
CVE-2008-2138 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "...
How severe is CVE-2008-2138?
CVE-2008-2138 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-2138?
Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server Portal.