Is Oracle HTTP susceptible to the same flaws as Apache 1.3?

Is it correct to assume Oracle HTTP server is vulnerable to the same vulnerabilities found in Apache Server 1.3?
Have any of the CPUs for Oracle Application Server (10.1.2.0.2) addressed the 'Expect Header' vulnerability (http://www.securityfocus.com/archive/1/441014) in Apache 1.3?

The vulnerability (CVE-2006-3918) was patched by the Oct 2006 CPU.
Message was edited by:
nholst

Similar Messages

  • Can you run Embedded PL/SQL Gateway and Oracle HTTP Server at the same time

    Hi,
    I know this will sound a bit odd but their is a business case for asking this. Can you run APEX via the Embedded PL/SQL Gateway and the Oracle HTTP Server at the same time? Would their be any security/stability/etc issues I'd need to worry about? I know that I'll need to run them on different ports.
    Thank you,
    Martin Giffy D'Souza
    [http://apex-smb.blogspot.com/]

    I think I've done this in the past. Theres no technical reason why you can't do this as far as I know.
    I can't remember if I used different ports or same port.

  • How to install oracle http server in the windows

    Hi,
    Can any one mention how to install oracle HTTP server in windows 2003 server machine?
    regards,
    suresh G.

    Hi,
    Which version of Oracle HTTP Server are you looking for ?
    Download link,
    http://www.oracle.com/technetwork/middleware/ias/downloads/101310-085449.html
    Here you will get both Apache version 1.3.34 for OHS based on Apache 1.3 and Apache version 2.0.55 for OHS based on Apache 2.0.
    Prerequisites
    http://docs.oracle.com/cd/B25222_02/quickinstall.1013/quickinstall/quick_install.htm#sthref9
    Installation steps
    http://docs.oracle.com/cd/B25222_02/install.1013/install/basic_install.htm#sthref274
    On the 1 st screen Select Advanced Installation Mode,
    And select only Oracle HTTP server in the 2nd screen
    Regards
    Fabian

  • Standalone oc4j and oracle 9i database on the same windows xp machine

    I m trying to deploy my j2ee application in my local system using standalone oc4j container(Oracle Containers for J2EE 10g (10.1.3.1)).To configure OC4j,I had to mention ORACLE_HOME=d:\oc4j as a user defined env variable.after that the oc4j started running normally.then i installed oracle 9i database in the same system to use it as the database for the application.During installation it prompts that ORACLE_HOME is alredady set.However the installation completes successfully.But when i try opening sql plus,it throws and error asking to check oracle_home.Its only after changing oracle home to d:\oracle,that sql plus opened and i could log in to it.But after that oc4j would not run saying it cannot find relevant files.Is it not possible to have standalone oc4j and a database for a J2ee application on the same system.if its possible,how can we go ahead?Thanks in advance

    user549113,
    Problem with ORACLE_HOME has been discussed several times already in this forum. I suggest you search the forum archives for "ORACLE_HOME".
    Good Luck,
    Avi.

  • Having two oracle clients installed at the same time

    Hi, I was wondering if there is a way to have two oracle clients installed at the same time on one computer, and if there is a way to be changing the default client between the two. I need to have installed the oracle client 10g and 8 versions on the same computer, because we have a problem with a legacy application that for some reason only works with version 8, and we need the 10g because our new applications requires 8.1 or later. We are still migrating to the new system but we developers need to have the two clients. Any help is appreciated. Thanks in advance.

    Is it possible, sure.
    Technically, clients before 8.1.5 were not multi-home compliant, so having Oracle 8 and Oracle 10g clients on the same machine is almost certainly not supported. On the other hand, I know that a number of developers at Oracle had combinations of Oracle 7 clients Oracle 8 clients, Oracle 8i clients, and Oracle 9i clients on their development machines at the same, so you shouldn't have too many major issues.
    Most "default client" issues come down to which ORACLE_HOME is first in the system's PATH. Ideally, you would leave the Oracle 8 ORACLE_HOME first in the path and explicitly reference the 10g ORACLE_HOME when configuring anything that relies on the 10g client.
    Justin

  • Is it possible to send several http requests at the same time?

    hi:
    is it possible to send several http requests at the same time in j2me application, or it's device specific.
    It's ok in my NOKIA SYMBIAN C++ application.
    regards
    Message was edited by:
    danielwang

    Is it possible to have 2 threads running at the same
    time at different times eg 1 repeats every 20
    miliseconds and the other 40 for example. Yes.
    http://java.sun.com/docs/books/tutorial/essential/concurrency/index.html

  • Http server in the same oracle home or not ?

    Hi, finally i could install oracle 10g 10.2.0.3 on windows vista. Now i want to install http server but i wonder if i have to install in the same oracle home or in another one. Some documents says yes another one not.

    oracle_sv wrote:
    I would like to keep 10g version. I have the cd companion. The fist time that i tried to install give some errors and after that i couldn´r start OracleDB console and EMOuch! I suspect that was due to installing HTTP Server binaries in your Oracle home?
    I have only installed HTTP Server on Linux, and I had a separate home for the Oracle database binaries and HTTP Server.
    The installation (at least on Linux) was straight forward, provided you have done your prep work by installing the correct RPM's, environment, etc.
    Once you have HTTP Server installed, you have to fulfil the rest of the APEX requirements (if not already done), such as:
    - Patch HTTP Server (for Linux, this is Application Server Patch 5983622)
    - Install XML DB
    - Install Oracle Text
    - Upgrade PL/SQL Web toolkit
    - Install APEX (I had 3.12 originally installed, but recently upgraded to 4.0 which was painless).
    - Configure your Apache/modplsql/conf/dads.conf in your HTTP Server home
    You will need to read the installation guides on how to do each of the above. You might have more luck doing this on Linux than Windows.
    If I was in your position and starting from scratch on this, I would be installing 11g, as it might not be so much work since APEX comes as part of 11g.

  • How to install oracle multiple homes in the same path

    Hi,
    In my environment i have multiple oracle home.
    for ex:
    /u01/oracle/product/10.2.0.3/
    /u01/oracle/product/10.2.0.4/
    /u01/oracle/product/11.2.0.1/
    The above are the oracle default home paths
    now i want to install 11.2.0.2 in the same path with different folder under the same name version
    may i know what are the pre-request parameter that i need to check in solaris 64 bit
    And i want to install oracle software alone
    while installing oracle software alone how about the file /var/opt/oracle/oratab and oracle oraInventory files
    whether it replace the old version oracle file. Please clarify
    Thanks in advance.

    Hello,
    By default, the Oracle Inventory directory is not installed under the Oracle Base directory.
    This is because all Oracle software installations share a common Oracle Inventory,
    ...The Oracle Inventory should be shared by all Oracle installations on the Server. So its location is unique.
    However, you may have several Oracle Base directories.
    Oracle Base is the root directory of the Oracle installation and may change from one major release to another one. However, the same Oracle Base may be used for several installations:
    http://download.oracle.com/docs/cd/E11882_01/install.112/e17163/glossary.htm#g998168
    Also, by default OUI suggest you the Oracle Base directory. In general you have something like "/u01/app/oracle". But you are free to set the Oracle Base directory you prefer.
    Hope this help.
    Best regards,
    Jean-Valentin

  • Oracle Reports: Opening within the same browser all the time

    Hi there,
    I am running Oracle Report 10g using Oracle AS 10.3.
    The report output is PDF to a browser.
    Each time I run the report, it opens within the same browser.
    Is there an option to open the report in a new browser all the time.
    http://server_name:port_number/reports/rwservlet?server=report_server_name&recursive_load=NO&paramform=NO&destype=CACHE&desformat=pdf&report=report_name.rep&orientation=portrait&paramter1=1
    Thanks for any help.
    Jim

    I guess you run the report from a form using WEB.SHOW_DOCUMENT? If so, use '_blank' as second parameter, this will open the given url in a new window.
    btw.. if you use forms to start a report you may consider to use RUN_REPORT_OBJECT to start the report instead of using the url-syntax.

  • Oracle AS and Oracle 9i Client on the same server

    Hello,
    We have a Window 2000 server with Oracle 9i Client. A number of applications running on this server relies on Oracle 9i Client. Could I install Oracle AS on the same machine without causing any problems to the applications using Oracle 9i client?
    Thanks
    Slava

    Oracle software is multi home aware - which means you can install 10 different Oracle products and versions, each in its own unique Oracle Home directory, and switch between and run all 10 different products - even at the same time (assuming sufficient resources on the platform).
    You cannot "+consolidate+" different Oracle Homes - it is an unwise thing to do. The Oracle Universal Installer (OUI) has the means to determine when installing a new product, whether or not you have the option to install into an existing Oracle Home.
    And with OUI you also have the means to uninstall products in which case you can remove the corresponding Oracle Home from your platform.
    Note though that despite multiple homes, certain configuration files will be shared (e.g. +/etc/oratab+ on Unix systems). In such a case you may need to manually update such a configuration file after removing an Oracle Home from your system.
    Oracle XE sports its own installer (setup.exe on Windows) - so it does not use OUI. But it is multi-home aware - and can co-exists with other Oracle products in their specific Oracle Homes.

  • Install Oracle Application Server on the same machine with Oracle Database

    Hello!
    I have already have installed on my laptop the oracle Database 10g, and i want to install on the same machine Oracle Application Server; can I do that? After i look on some threads on this forum I understand that all I have to do is to change the default port 1521 of the database to antoher ..let's say 1523...how can I change the port? what files do i have to modify? Oracle Application server can work in good conditions with Oracle XE or I will have the same problem?
    My SO is Windows XP Professional SP II, all updates, 512RAM, 2Ghz-CPU
    Thanks!

    Well, you'll have some problems to run simultaneously Database and AS with 512 Mb...
    Apart from that, you don't need to start two listeners, you can use just one (the highest version) for both DBs.
    If, for any reason, you want to use two, you can change the port within LISTENER.ORA file, normally in ORACLE_HOME\network\admin.

  • Opening OEM for two Oracle 11gR2 Databases in the same web browser automatically log out.

    Hi to everyone,
    I have an issue regarding Oracle Enterprise Manager in 11gR2. I have two database (SWPROD, PDPROD) in a single server. When I open the OEM URL for  SWPROD it is successfully logged on but when I open the OEM URL for PDPROD and successfully logged on the other tab for SWPROD will automatically logged out. And when I switch to the other tab for PDPROD it is also automatically logged out. Both OEM URL is open in a single web browser like Mozilla Firefox. What would be the reason why both OEM URL will be logged out when I open them at the same time?
    Thank you for your incoming response.

    Well it seems the only way to clear these out of EM was to shut BOTH RAC nodes down and power them up one at a time.  Now the updates aren't shown as required and my compliance score is where it should be.
    Is this a bug ?  Seems pretty stupid to have to shut down both RAC nodes to fix this.  Powering a single RAC node off and back on did not clear this.
    Unless i'm missing something??

  • Is the interface of Oracle 10g XE is the same of Oracle 10g or 11g?

    Are the interface, functions the same?
    I am wondering after I practice performing DBA tasks using 10g XE.
    How much do I know about the real Oracle?
    Thanks.

    Hi,
    If you will perform the tasks by SqlPlus(the command line), it will be almost the same as 10g other edtions.
    If you are saying by visual tools, XE is using a apex based administration tool for basic management, other edtions are using Enterpirse Manager Database Control or Grid Control, more powerful than XE's , and EM is not available for XE.
    You also can download a version of any other Edtion of 10g or 11g, you can use it for study purpose, free of charge. but no offical support.
    Or, you even can buy a personal edtion of 10g or 11g, and you can have support.
    Peter

  • Oracle Read-Ahead: not the same as look-ahead, yes?

    Hi,
    I've tried to understand the Oracle Read-Ahead systems, and I think I undersand how it works, though I'd like to assert that I am not mistaken.
    From what I've managed to understand in the Oracle documentation, the Oracle read-ahead mechanism is mostly used for sequential accesses of data blocks. For example, to perform operations like table scans.
    In such cases, Oracle will for example use a physical operation called scattered read.
    The scattered read, in turn, is configured in the ini.ORA by a parameter name something like db_multiblock_read_count. Having a multiblock read count of 60, will make the scattered read operation read 60 sequential data blocks from disk, starting with the data block that was requested in the operation.
    From what I've gathered, this is the basis of the Read-ahead mechanism. It is use mult block operations do read data instead of single bock operations.
    If what I've said so far is correct. There are two things that I'd like to know:
    1.
    Those 60 blocks read by the sctarred read. Do they go directly into the database buffer cache? Or are they loaded first in to a lower level cache, like a scattered read cache?
    Thus, if the table scan requested the page 1. And the scattered read operation fetched the database pages 1 to 60. I assume that only page 1 would be transfered to the buffer cache. Later on, when the table scan requested for page 2, the buffer cache would retrieve that page from the scattered read cache into the buffer cache. Or is this completly wrong? And when the scattered read gets pages 1 to 60. It automatically dumps those data pages into the buffer cache into random positions of the main buffer?
    2.
    With Oracle read-ahead, table scans and other such physical operations will always incur scattered read waits periodically. For example, every 60 pages the table scan incurs in another scattered read wait correct?
    3.
    Reading-ahead In oracle only anticipates the database page needs of a physical operator a specific point in time, yes? The following does not happen:
    While the table scan is currently on page 50, having another 10 more pages left in the database buffer, some background process decides that it is a good idea request another fetch for 50 more data pages. In such a way that the forground thread processing the table scan never has stop in read IO.
    This would be called looking-ahead, and it is not an Oracle feature, is it?
    Thank you for your insight.
    I've performed some tests where though the table size of a data transformations remain the same (1GB) but the time I take to process the source table into my output varies. The processing time for each record increased greatly from test to test. But I noticed that the wait time of the data transformation remained constant, though the cpu time increased greatly. THe increase in CPU time means that the Time Until Next Buffer fetch was reduced, which would give more time for the system to look-ahead. Eventally I could have made the CPU time so great, that if REad IO was being performed in anticipation it would be theortically possible for the READ wait time to be 0. Which I know is not going to happen. So I'd just to be certain of how the read-ahead works.
    My best regards.

    sono99 wrote:
    Hi,
    I've tried to understand the Oracle Read-Ahead systems, and I think I undersand how it works, though I'd like to assert that I am not mistaken.
    From what I've managed to understand in the Oracle documentation, the Oracle read-ahead mechanism is mostly used for sequential accesses of data blocks. For example, to perform operations like table scans.
    In such cases, Oracle will for example use a physical operation called scattered read.
    The scattered read, in turn, is configured in the ini.ORA by a parameter name something like db_multiblock_read_count. Having a multiblock read count of 60, will make the scattered read operation read 60 sequential data blocks from disk, starting with the data block that was requested in the operation.
    From what I've gathered, this is the basis of the Read-ahead mechanism. It is use mult block operations do read data instead of single bock operations.
    Am not sure if you meant reading multiple blocks at the same time or Read ahead cache features provided by some storage devices. But to me it seems you are talking about MBRC (Multiblock read count) and not about read ahead cache provided by storage vendors.
    If what I've said so far is correct. There are two things that I'd like to know:
    1.
    Those 60 blocks read by the sctarred read. Do they go directly into the database buffer cache? Or are they loaded first in to a lower level cache, like a scattered read cache?
    Thus, if the table scan requested the page 1. And the scattered read operation fetched the database pages 1 to 60. I assume that only page 1 would be transfered to the buffer cache. Later on, when the table scan requested for page 2, the buffer cache would retrieve that page from the scattered read cache into the buffer cache. Or is this completly wrong? And when the scattered read gets pages 1 to 60. It automatically dumps those data pages into the buffer cache into random positions of the main buffer?
    If my mbrc is 60, and none of the blocks are in buffer and table size is more than 60 blocks then entire 60 blocks would get transferred to buffer cache. There is nothing called scattered read cache in the architecture of Oracle.
    2.
    With Oracle read-ahead, table scans and other such physical operations will always incur scattered read waits periodically. For example, every 60 pages the table scan incurs in another scattered read wait correct?
    Yes db file scattered read wait event would mean that another physical IO has been initiated for fetching next blocks of records.
    3.
    Reading-ahead In oracle only anticipates the database page needs of a physical operator a specific point in time, yes? The following does not happen:
    While the table scan is currently on page 50, having another 10 more pages left in the database buffer, some background process decides that it is a good idea request another fetch for 50 more data pages. In such a way that the forground thread processing the table scan never has stop in read IO.
    This would be called looking-ahead, and it is not an Oracle feature, is it?
    Yes I do not think so it is an Oracle feature but some storage vendor provides it. It is also known as Read ahead.
    Thank you for your insight.
    I've performed some tests where though the table size of a data transformations remain the same (1GB) but the time I take to process the source table into my output varies. The processing time for each record increased greatly from test to test. But I noticed that the wait time of the data transformation remained constant, though the cpu time increased greatly. THe increase in CPU time means that the Time Until Next Buffer fetch was reduced, which would give more time for the system to look-ahead. Eventally I could have made the CPU time so great, that if REad IO was being performed in anticipation it would be theortically possible for the READ wait time to be 0. Which I know is not going to happen. So I'd just to be certain of how the read-ahead works.
    My best regards.I did not understood your last para.
    Regards
    Anurag

  • Connecting DB Oracle/SQL server using the same SQL Navigator  release 5.1.0

    I have
    SQL Navigator release 5.1.0.655 installed in my desktop
    License version X-pert Edition
    Licensed Options
    PL/SQL Debugger
    CodeXpert
    Knowledge Xpert For Pl/SQL
    Xper Tuning
    Currently I have the access of Oracle DB using this SQL navigator and MS-SQL server using MS-Sql server Query Analyzer
    My question is -- using the same SQL Navigator can I connect MS-SQL server DB/Tables and can I run sql query using this..
    Thanks in advance.
    Mash

    Why, in an Oracle forum, are you asking a question about a Quest product connecting to a Microsoft product?
    How does this relate to the Oracle Database?

Maybe you are looking for

  • How do I Include content (another page) in a WEeb [page

    I need some help. I've been using MS Front Page for the last 6-7 yrs. In MS FP there is a way to include an html file into another html file. Example: I have a Web site that has 10 pages. Each page is made up of a 3 column table with a menu file in t

  • The music in my iTunes library won't sync to my iPod touch

    I have a 32 GB 3rd iPod touch. And earlier after I had finished downloading some new music, I tried to sync my iPod. First it told me I had to restore my iPod, because it couldn't be read. I did. And three hours later, it was done. So once again, I p

  • Good quality quicktime movie looks poor when played thru Final Cut timeline

    I created a quicktime file with moving text in After Effects 6.5..when i play the movie file it looks fine..no aliasing or jagged edges on the text... when I import the .mov file into finalcut (4.5HD) and immediately launch & play it in the viewer, i

  • ADF UI for HT Submit Error

    Hi guys, I've created an ADF UI for a HT using the add ADF taskflow based on human task method. From the generated data control I added on the taskdetails.jspx page the full task details (history, comments, attachments, payload, task actions etc.) -

  • Incorrect number

    When I try to add the number it tells me that it is incorrect but it is the exact number that shows up on the caller ID. Does it need dashes or spaces?