
CIA RESEARCH
Alerts
[CIA-1028-Alert] Oracle Reports File Access and Destruction via HTML parameters
Summary:
A vulnerability was reported in Oracle Reports Server allows a remote user to overwrite arbitrary files
on the server via two application parameters.
Technical Details:
A user that has been authenticated can overwrite files on the Oracle Reports server using a
maliciously crafted ‘desname’ parameter. The request will be processed with the privileges
associated with the Oracle User account. On Microsoft Windows systems, any file can be overwritten,
resulting in potential loss of critical files, and possibly damage to the underlying operating
system.
The “desformat” parameter allows access to arbitrary files by producing error messages that contain
fragments of information from within the requested filename. For example:
http://OracleApplicationServer:7778/reports/rwservlet?
server=myserver+report=test.rdf+userid=scott/
tiger@iasdb+destype=file+MODE=CHARACTER
desformat=/etc/passwd
Solution:
Unofficial workarounds for these security issues are available from the links below:
Red Database Security: Overwrite any file via desname in Oracle Reports
Red Database Security: Read parts of any file via desformat in Oracle Reports
CVE Reference:
GENERIC-MAP-NOMATCH
SecurityTracker Number(s):
1014524, 1014527
Vendor URL:
http://www.oracle.com
About the Cenzic CIA Team:
Cenzic Intelligent Analysis (CIA) is Cenzic’s research arm that focuses on continuous
research for application vulnerabilities. Industry Research, Vulnerability assessment,
penetration testing, and security testing — that’s what Cenzic Intelligent Analysis
Research is all about. Cenzic has dedicated experts whose sole job is to perform ongoing
research to find not only common vulnerabilities but also vulnerabilities found in
customer applications and make them available to our customers and to the community at large.
About Cenzic:
Cenzic provides Hailstorm®, the revolutionary enterprise software suite for automated
application security assessment and compliance that allows corporations and government
organizations to dramatically improve the security of commercial and custom applications.
Hailstorm enables security experts, QA professionals, and developers to work together
to assess, analyze, and remediate applications for security vulnerabilities, and verify
compliance with security policies. Benefits include reduced security risk and liability,
lower development and testing costs, and faster time-to-market. Cenzic’s customers are
currently in the financial services and e-marketplaces sectors. For more information
visit www.cenzic.com or call 1-866-4-CENZIC

|