Test For Oracle Application Server

OWASP 2013-A9 OWASP 2017-A9 OWASP PC-C3 WASC-14

Oracle application server was designed to enable scalability of web and database based applications to use more than one database instances. The features of Oracle application server includes deployment model with multiple deployment options, vast availability of methods for web content etc. There are some potential vulnerabilities found in the component of Oracle Application Server. The vulnerabilities may be due to configuration issues associated with the Portal Listener and modplsql or customers grant public access to PL/SQL procedures. These vulnerabilities allow unauthorized access to administrative pages and back-end Oracle databases.

Impact

The impact include:-

  • Reading, updating and deleting arbitrary data/tables from the database
  • Executing commands on the underlying operating system

Mitigation / Precaution

The vulnerabilities can be fixed by:-

  • Using updated patches.
  • Using the latest version of Oracle application server.

Latest Articles