漏洞名称: Oracle HTTP Server MOD_OSSO Partner Application Cookie Expiration Weakness
漏洞编号: ICST-CA-2005-123
漏洞说明: Oracle HTTP Server的mod_osso模组无法正确令cookies失效,可能导致有心人士透过cookie获得未合法授权的存取。
影响平台: Oracle Oracle HTTP Server 9.0.2 .3
影响状况: Cookies Authorization Bypassing
解决方案: Oracle提供下面两个如何更新的网址:
Pre-installation notes for Oracle Database Server
http://metalink.oracle.com/metalink/plsql/ml2_docume...ase_id=NOT&p_id=311062.1Pre-installation notes for Oracle Application Server
http://metalink.oracle.com/metalink/plsql/ml2_docume...ase_id=NOT&p_id=311038.1 参考资料: Oracle HTTP Server MOD_OSSO Partner Application Cookie Expiration Weakness