Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote malicious users to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
oracle application server release_1.0.2.0.1 |
||
oracle oracle8i 8.1.7_r3 |