Executive brief
Oracle Webserver 2.1 and earlier contains a configuration flaw that allows anyone with access to the 'oracle' system account to gain full administrative (root) control over the server. This occurs because the web server runs with high privileges but relies on configuration files that can be modified by a lower-privileged user. An attacker who compromises the database account could use this to take over the entire operating system, modify any file, or disrupt services.
Technical details
The Oracle Webserver (versions 2.1 and earlier) is installed with the setuid bit set, allowing it to run with root privileges. However, the configuration files and the software directory tree are owned by the 'oracle' user account rather than root. This insecure permission model allows an attacker who has obtained access to the 'oracle' account (either locally or via remote exploit) to modify the web server's configuration. By doing so, the attacker can instruct the setuid process to run under a different account or exploit the fact that the server opens log files as root to append data to or overwrite arbitrary system files, leading to full system compromise.
Affected products
- Oracle Webserver 2.1 and earlier
Timeline
- 1997-09-19: disclosed: Initial disclosure on Bugtraq mailing list
- 1997-09-19: advisory: NVD publication date