CVE-2005-1383
published 2005-05-03CVE-2005-1383: The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access…
PriorityP352high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
30.61%
98.0th percentile
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for HTTP requests to port 7778 (Oracle Webcache) targeting sensitive diagnostic/status paths such as /dmsoc4j/AggreSpy, /server-status, and /dms0, which bypass mod_access restrictions enforced on port 7779 (OHS). ↗
- →Alert on inbound connections to TCP port 7778 from untrusted/external sources, as this is the Webcache port used to bypass mod_access restrictions in Oracle Application Server. ↗
- →Look for query parameters format=metrictable&nountype=ohs_child&orderby=Name in HTTP requests, which indicate exploitation of the AggreSpy diagnostic endpoint via the Webcache bypass. ↗
- ·The bypass only applies when UseWebcacheIP is disabled in the OHS configuration. If UseWebcacheIP is enabled, the Webcache IP is recognized and mod_access restrictions are enforced correctly. ↗
- ·Affected versions span OHS component 1.0.2 through 10.x; verify your Oracle Application Server version falls within this range before applying detection logic. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=111472266123952&w=2http://secunia.com/advisories/15143http://www.osvdb.org/15908http://www.red-database-security.com/advisory/oracle_webcache_bypass.htmlhttp://www.securityfocus.com/bid/13418https://exchange.xforce.ibmcloud.com/vulnerabilities/20311http://marc.info/?l=bugtraq&m=111472266123952&w=2http://secunia.com/advisories/15143http://www.osvdb.org/15908http://www.red-database-security.com/advisory/oracle_webcache_bypass.htmlhttp://www.securityfocus.com/bid/13418https://exchange.xforce.ibmcloud.com/vulnerabilities/20311
2005-05-03
Published