Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
Affected Software
Name |
Vendor |
Start Version |
End Version |
Application_server |
Oracle |
1.0.2 (including) |
1.0.2 (including) |
References