CRM On Demand - Administration (MOSC)

MOSC Banner

Apache 2.0.52 vulnerability : Web Server Expect Header XSS

edited Feb 13, 2014 12:00PM in CRM On Demand - Administration (MOSC) 3 commentsAnswered

Hi,

I hope someone can help me out here. We recently had a penetration test run on our network and the following vulnerability was identified

"The remote web server fails to sanitize the contents of an 'Expect' request header before using it to generate dynamic web content. An

unauthenticated, remote attacker may be able to leverage this issue to launch cross-site scripting attacks against the affected service,

perhaps through specially crafted ShockWave (SWF) files."

This can be fixed by upgrading our current version of Apache Webserver 2.0.52 to 2.0.63. We are running Oracle Applications 11.5.10.2. Was there a patch released by Oracle to fix this vulnerability? I don't think I should be upgrading Apache on it's own

Tagged:

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center