CVE-1999-1125
published 1997-09-19CVE-1999-1125: Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who…
PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.72%
88.6th percentile
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | http_server | <= 2.1 | — |
| oracle | http_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Oracle Webserver 1.0/2.1 Permission privileges management
vuldb·2026-04-17·CVSS 10.0
CVE-1999-1125 [CRITICAL] Oracle Webserver 1.0/2.1 Permission privileges management
A vulnerability labeled as problematic has been found in Oracle Webserver 1.0/2.1. Affected by this issue is some unknown functionality of the component Permission Handler. Such manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-1999-1125. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-59f3-q6cq-qcpj: Oracle Webserver 2
ghsa_unreviewed·2022-04-30
CVE-1999-1125 [HIGH] GHSA-59f3-q6cq-qcpj: Oracle Webserver 2
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
1997-09-19
Published