Baran İpek Oracle and Java

October 3, 2010

Vulnerability in OC4J

Filed under: java — baranipek @ 6:52 pm

I encountered one of oc4j vulnerability and want to share this experience. Container_tabs.jsp  is  reachable and vulnerable for Cross Site Scripting that is not part of my ear file  when you type url like http://domain/webapp/jsp/container_tabs.jsp. This jsp is located under home/j2ee/applications/webapp/jsp folder  and this page could be exploited by attackers to execute arbitrary scripting code. The solution is enable securty_mod if it isn’t  or you need to remove this page. The last option is waiting for a patch from Oracle but as we know Oracle tend to support Weblogic instead Oc4j.

For further reading

http://hungred.com/web-development/solutions-crosssite-scripting-xss-attack/

Leave a Comment »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Connecting to %s

Theme: Rubric. Blog at WordPress.com.

Follow

Get every new post delivered to your Inbox.