CVE

Id
3237  
CVE No.
CVE-2001-0419  
Status
Candidate  
Description
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.  
Phase
Proposed (20010524)  
Votes
MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Ziese | REVIEWING(1) Williams  
Comments
Frech> XF:oracle-appserver-ndwfn4-bo(6334) | Christey> At http://otn.oracle.com/deploy/security/alerts.htm, | in an item titled "Oracle Application Server Buffer Overflow," | Oracle says that it was "Unable to reproduce vulnerability"