Family: Databases --> Category: infos
Oracle 9iAS Java Process Manager Vulnerability Scan
Vulnerability Scan Summary
Tests for Oracle9iAS Java Process Manager
Detailed Explanation for this Vulnerability Test
It is possible to obtain the list of Java processes running on the
remote host anonymously, as well as to start and stop them.
The remote host is an Oracle 9iAS server. By default, accessing
the location /oprocmgr-status via HTTP lets a possible hacker obtain
the list of processes running on the remote host, and even to
to start or stop them.
Restrict access to /oprocmgr-status in httpd.conf
High / CVSS Base Score : 7
Click HERE for more information and discussions on this network vulnerability scan.