Oracle9i SOAP Vulnerability Found

Oracle9i SOAP Vulnerability Found

Written By
Lisa Vaas
Lisa Vaas
Feb 24, 2004
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Oracle Corp. last week revealed that a potential security vulnerability has been discovered in its Oracle9i Application Server and Oracle9i Database Server.

The vulnerability is within SOAP (Simple Object Access Protocol) messages whose XML contains carefully constructed DTDs (Data Type Definitions), according to Oracle Technology Networks security alert, which can be viewed here. The alert notes that SOAP is the basis of Web services, which are therefore affected as well.

To exploit the vulnerability, a malicious user requires access to SOAP-enabled servers. A knowledgeable attacker can exploit the vulnerability to cause a DoS (denial of service) against the database and application servers.

XML and SOAP are installed by default in both the database and application servers when the Oracle HTTP Server is installed.

Risk is high in Oracle9i Application Server Release 2, Version 9.0.2.1 and earlier, since authentication to SOAP is not turned on by default. Risk is only moderate post-Release 2, Version 9.0.2.1 and in Oracle9i Database Server, since those later versions require authentication to SOAP.

Unauthenticated clients dont pose a threat if SOAP is protected by client authentication before the processing of SOAP XML data structures. Oracles security alert gives the example of SSL sessions protected by Client X.509 certificates as being protected against unauthenticated clients.

Disabling SOAP is a workaround for sites not using SOAP. Thats done by removing or renaming the following SOAP library, which is delivered in the following JAR file: [Oracle Home]/soap/lib/soap.jar.

Oracles alert strongly recommends customers apply a workaround or patch and that they review the severity rating for this alert and patch accordingly. Click here for a definition of severity ratings, and click here for the patch download.

Check out

eWEEK.coms Database Center

at http://database.eweek.com for more database news, views and analysis.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.