Vulnerability Scanning Solutions, LLC.
Our Process
What We Scan For
Sample Report
Client List
Contact Us
What We Scan For
Family: Databases --> Category: infos

Oracle 9iAS SOAP configuration file retrieval Vulnerability Scan

Vulnerability Scan Summary
Tries to retrieve Oracle9iAS SOAP configuration file

Detailed Explanation for this Vulnerability Test

In a default installation of Oracle 9iAS v., it is possible to
access some configuration files. These file includes detailed
information on how the product was installed in the server
including where the SOAP provider and service manager are located
as well as administrative URLs to access them. They might also
contain sensitive information (usernames and passwords for database

Modify the file permissions so that the web server process
cannot retrieve it. Note however that if the XSQLServlet is present
it might bypass filesystem restrictions.

More information:

Also read:
Hackproofing Oracle Application Server from NGSSoftware:
available at

Threat Level: Medium

Click HERE for more information and discussions on this network vulnerability scan.


P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.