Executive brief
Oracle Webserver 2.1 is susceptible to a denial-of-service attack when processing specific database-driven web requests. By sending a specially crafted, overly long web request, a remote attacker can cause the server to crash or stop responding. This disrupts the availability of web applications and services hosted on the affected server, potentially impacting business operations and customer access.
Technical details
A denial-of-service vulnerability exists in Oracle Webserver 2.1 specifically when it is configured to serve PL/SQL stored procedures. The vulnerability is triggered by a long HTTP GET request containing an excessively large parameter string (approximately 2600 characters or more). When the server attempts to process this request, it fails silently without logging the error, leading to a service crash. This is a remote, unauthenticated attack that impacts service availability. Version 2.0 of the software is reportedly not affected by this specific issue.
Affected products
- Oracle Webserver 2.1
Timeline
- 1997-07-23: disclosed: Vulnerability disclosed on Bugtraq mailing list
- 1997-07-23: advisory: NVD published date