漏洞名稱: Oracle HTTP Server MOD_OSSO Partner Application Cookie Expiration Weakness
漏洞編號: ICST-CA-2005-123
漏洞說明: Oracle HTTP Server的mod_osso模組無法正確令cookies失效,可能導致有心人士透過cookie獲得未合法授權的存取。
影響平台: Oracle Oracle HTTP Server 9.0.2 .3
影響狀況: Cookies Authorization Bypassing
解決方案: Oracle提供下面兩個如何更新的網址:
Pre-installation notes for Oracle Database Server
http://metalink.oracle.com/metalink/plsql/ml2_docume...ase_id=NOT&p_id=311062.1Pre-installation notes for Oracle Application Server
http://metalink.oracle.com/metalink/plsql/ml2_docume...ase_id=NOT&p_id=311038.1 參考資料: Oracle HTTP Server MOD_OSSO Partner Application Cookie Expiration Weakness