cbcvebase.
CVE-1999-1125
published 1997-09-19

CVE-1999-1125: Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who…

PriorityP337critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.72%
88.6th percentile
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

Affected

2 ranges
VendorProductVersion rangeFixed in
oraclehttp_server<= 2.1
oraclehttp_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.