Discussions
Be sure you're subscribed to NetSuite communication to stay in the know about monthly happenings, updates and announcements. Subscribe
McAfee Vulnerability !!!
Netsuite Team,
We have recently had the McAfee scan for our website for customers security sake.
It has given one security vulnerability as following:
Name : Oracle 9iAS Dynamic Monitoring Services
Category : SQL - Database
Impact : Information Disclosure
Description:
In a default installation of Oracle 9iAS, it is possible to access the Dynamic Monitoring Services pages anonymously. Access to these pages should be restricted.
http://DOMAIN/dms0
General Solution:
Edit the httpd.conf file to restrict access to /dms0.
Additional Information:
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.