Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-1999-1125 | First vendor Publication | 1997-09-19 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 10 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-1125 |
CAPEC : Common Attack Pattern Enumeration & Classification
Id | Name |
---|---|
CAPEC-17 | Accessing, Modifying or Executing Executable Files |
CAPEC-35 | Leverage Executable Code in Nonexecutable Files |
CWE : Common Weakness Enumeration
% | Id | Name |
---|
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
9414 | Oracle Webserver Configuration File Ownership Weakness |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:25:03 |
|
2024-11-28 12:03:51 |
|
2021-05-05 01:00:51 |
|
2021-05-04 12:00:59 |
|
2021-04-22 01:01:13 |
|
2020-10-14 01:00:44 |
|
2020-05-23 01:35:10 |
|
2020-05-23 00:14:13 |
|
2016-10-18 12:00:47 |
|
2016-04-26 11:28:42 |
|
2013-05-11 11:57:55 |
|