Oracle 8.1.7 with OSE affected by HTTP TRACE / TRACK vulnerability
Hi All,
I had no luck using the search function for the problem I'm facing. As for the possibility of posting this in the wrong category, I apologize.
I'm supporting an application that uses Oracle 8.1.7 in a Solaris 9 environment. The web server in use is Apache 1.3.12.
In a security scan, the HTTP TRACK/TRACE vulnerability was found on port 8080. I immediately checked the apache config file (httpd.conf) and found that the apache instance runs on port 7777 and the TRACE and TRACK method is already disabled.
With some help from a colleague, I found that the Oracle Servlet Engine (OSE) admin service is running on port 8080. Disabling this service is not an option because it renders the application unusable. How can I disable these HTTP methods?
If more information is required, do ask.
It still seems incredibly low priority to me - I'm not sure if you could even exploit that vulnerability in this instance, even somone did get onto your network.
But, you could configure requests to be routed via the http server http://download.oracle.com/docs/cd/A87860_01/doc/java.817/a83720/modi_apa.htm#77221 - which will filter out the track/trace requests, but I'm not sure if you could disable direct access to the servlet engine.
Apart from that, not really sure.
Similar Messages
-
HOW INCREASE SGA IN ORACLE RAC 10 G WITH 2 NODES
How increase sga_max_size, sga_target in ORACLE RAC 10 G WITH 2 NODES;
i have oracle 10g in unix hp-ux 11i in rac (2 nodes)
with sga 8g; and i want to increase 12g;
i can alter these parameters without shutdown the entire database ?; , i can alter and take these change in one node first and later de second node?
i used in first node :
1- alter system set sga_max_size=16g scope spfile;
2- alter system set sga_targer=12g cope spfile;
later i restard all intance one by one:
srcvtl stop instance -d my_database -i my_instance1 -o immediate;
srcvtl start instance -d my_database -i my_instance1
3- in second node.
srcvtl stop instance -d my_database -i my_instance2 -o immediate;
srcvtl start instance -d my_database -i my_instance2
but my sga is the SAME 8G.. WHY NOT CHANGE...
i changed these parameters and restar my instance in first node later stop and start using srvctl the second node but my sga not change. continue in 8g ;however these changes are in spfile so;
prd2.sga_max_size=8589934592#internally adjusted
prd1.sga_max_size=8589934592#internally adjusted
*.sga_max_size=17179869184
prd2.sga_target=8589934592
prd1.sga_target=8589934592
*.sga_target=12884901888
prd2.thread=2
prd1.thread=1
how i can apply these change node by node or i need shutdown the entire database?
need to make these changes without affecting my application because i can not shutdown the both node...
Edited by: user568681 on 02-sep-2010 14:32Hi,
I just checked on a test RAC configuration (HP-UX, 10.2.0.4)
You don't need to stop the database.
Keep your "rolling" original scenario but change :
alter system set sga_max_size=16g scope spfile;
alter system set sga_target=12g cope spfile;by
alter system set sga_max_size=16g scope spfile sid = 'PRD1';
alter system set sga_target=12g scope spfile sid = 'PRD1';
alter system set sga_max_size=16g scope spfile sid = 'PRD2';
alter system set sga_target=12g cope spfile sid = 'PRD2';Actually
alter system set sga_max_size=16g scope spfile;
alter system set sga_max_size=16g scope spfile SID='*';changes globally the values for every instance in the spfile ("*.XXXXXX" is updated) but it does not remove the specific entries already assigned to one particular instance (and it is your case !)
Alternatively you could reset the values assigned specifically to one instance with "alter system reset" to have only "*.XXXX" for those parameters.
Best regards
Phil -
Oracle Workflow 2.6 with Oracle 8.1.7 for linux
Is Oracle Workflow Server 2.6 available for Linux as a
standalone product against an Oracle 8.1.7 database?
Oracle Workflow does not seem to be included in the Integration
Server option with the 8.1.7 installation.
I've only found the Oracle Workflow Server included with the 9i
database. Will this work with 8.1.7 as well or does it require
9i db?
Thanks in advance for your help,
Josi AntonioIs Oracle Workflow Server 2.6 available for Linux as a
standalone product against an Oracle 8.1.7 database?
Oracle Workflow does not seem to be included in the Integration
Server option with the 8.1.7 installation.
I've only found the Oracle Workflow Server included with the 9i
database. Will this work with 8.1.7 as well or does it require
9i db?
Thanks in advance for your help,
Josi Antonio -
Oracle 10g R2 installation with ASM+RAC
Gurus,
Need some suggestuon on Oracle 10g R2 installation with ASM and RAC option.
We have found many documents on the Oracle, HP, HP-Oracle CTC and third party web sites, but nothing that is specific to this particular combination of separate
ORACLE_HOMEs, ASM and 10g RAC CRS. It is unclear for me from the documentation how this combination of ASM and 10.2g RAC may best be installed.
The high level steps i got after reading lot of docs as follows - but i am not sure whether these are correct or not. if they are correct, can any one share their experience/notes please?
1) Install CRS
2) Install RDBMS for ASM HOME - create separater oracle home for ASM instance using OUI
3) Install RDBMS for RAC Database Home - create separater oracle home for RAC database using OUI
4) Create ASM database using DBCA -
5) Use dbca to create database.Oracle provides 'paint by numbers' tutorials called 'Oracle By Example'. (Go to OTN, check under the Training tab)
They have one for a Windows based ASM/RAC that you might want to review. Not your specific environment, but the steps will be dag-nabbed close.
I recommend walking the path (http://otn.oracle.com >> training:OBE >> Database 10g Release 1:VMWare:Installation
http://www.oracle.com/technology/obe/obe10gdb_vmware/install/racinstallwin2k/racinstallwin2k.htm -
How to create a new Oracle OSB project automaticaly with script without IDE
Hello,
I want to create automatically an "Oracle service bus project" and an "Oracle service bus configuration project" with scripts (ANT or Maven or ...) without using IDE, without using workshop or Eclipse. I want to create automatically (ANT or Maven) just a skeleton of an OSB project witch i can use after in workshop.
I want to create 1 "Oracle service bus configuration project" with many "Oracle service bus project" automatically (ANT or Maven or scripts) witch i can use after in workshop. How to create a new Oracle OSB project automaticaly with script without IDE ? How can i do this ?
I'm using Oracle service bus 10.3.1
Thank you for your help.Thank you for your response,
I do not want to just create the services (proxy services and business services) but I want to create a template for 40 OSB project with the same scripts ANT/Maven.
Template="Oracle service bus configuration project" + "Oracle service bus project" + services of 40 OSB projects
The goal is that I have more than 40 projects to create and just the name of the projects that changes (when I say the name of the project ie the name of the OSB project, the name of proxy services and the name of business services ).
So I want to give my script (ANT/Maven) the name of 40 OSB project and the script must generate the skeleton of the 40 projects at once time and after generation of skeleton of the 40 project, I will import them in the workshop to add manually mapping and routing and other things that differs from one project to another.
So i want to generate automatically a skeletons of 40 OSB projects using a script (ANT / Maven) and I give to the script juste the names of the 40 projects.
I want to create a "Oracle service bus configuration project" and "Oracle service bus project" automatically of 40 OSB projects (ANT or Maven or scripts) witch i can use after in workshop.
I want to create one 'template' of all 40 projects in the same time, with the same directory structure (Transforlation, Business services, proxy services, WSDL .....) and all 40 project have the same transport, just the names of projects and services witch changes and i can give to the script all names of projects and services and i can give also all WSDL.
Regards,
Tarik -
Installing Oracle 8.1.7 with PS on Win 2000 cluster
Sorry for bad English.
I'm have problem. I have Oracle 8.1.7 with PS. I need setup Oracle with Parallel Server on cluster with Windows 2000 AS, but during setup Oracle no found cluster. In documentation talk about need Operation System Depend layer from vendor OS.
What me do? Where take OSD? Where reason?Hi Satish,
You need to install "Oracle Data Provider for .NET" on the target machine, and it needs to be the same version as the one you used to build the assemblies.
Christian Shay
Oracle -
At least 6 differences between Oracle 9i and 10g with complete understan
Hi 2.
At least 6 differences between Oracle 9i and 10g with complete understanding of each difference .
cheersHi,
Forum thread already opened by you
check what is the major difference between 9i and 10g
regards,
kaushal -
Best practice for oracle 10.2 RAC with ASM
Did any one tried/installed Oracle 10.2 RAC with ASM and CRS ?
What is the best practice?
1. separate home for CRS, ASM and Oracle Database?
2. separate home for CRS and same home for ASM and Oracle Darabase?
we set up the test environment with separate CRS, ASM and Oracle database homes, but we have tons of issues with the listener, spfile and tnsnames.ora files. So, seeking advise from the gurus who implimeted/tested the same ?I am getting ready to install the 10gR2 database software (10gR2 Clusterware was just installed ) and I want to have a home for ASM and another for database as you suggest. I have been told that 10gR2 was to have a smaller set of binaries that can be used for the ASM home ... but I am not sure how I go about installing it. The first look at the installer does not seem to make it obvious...Is it a custom build option?
-
How to install Oracle BPEL Process Manager with the BEA WebLogic
Hi ,
I will install Oracle BPEL Process Manager with BEA WebLogic 9.2(MP2). I have download orabpel_10133_WebLogic.zip ,then Modify the following mandatory installation properties in the orabpel_10133_WebLogic\bpelDomain.properties file:
# BEA_HOME is the path where Weblogic is Installed
BEA_HOME=/opt/bea
# JAVA_HOME is the path of jdk folder inside your weblogic
JAVA_HOME=/opt/bea/jrockit90_150_10
# DOMAIN_HOME is the path where you wish to create your domain called BPELDomain
DOMAIN_HOME=/opt/bea/user_projects/domains
# APPS_HOME is the path where you wish to copy your applications and adapters that are required for oracleBPELServer
APPS_HOME=/opt/bea/user_projects/apps
# BEA_HOME is the path where BPEL PM is Installed
BPEL_HOME=/home/oracle/bpel/product/10.1.3.1/OraBPEL_1/bpel
# DRIVER_TYPE is the datasource class that installable use to create a datasources for oracleBPELServer
DRIVER_TYPE=oracle.jdbc.xa.client.OracleXADataSource
# DB_URL is the url to connect to orabpel schema
DB_URL=jdbc:oracle:thin:@16.157.134.17:1521:orcl
# DB_USER is the user Id for orabpel shema in database
DB_USER=ORABPEL
#DB_PASSWORD is the password for orabpel schema in database
DB_PASSWORD=bpel
#BPEL_SERVER_NAME is the server i.e. to be created under BPELDomain
BPEL_SERVER_NAME=oracleBPELServer
#PROXY_HOST is the Host name of the proxy server
PROXY_HOST=www-proxy.us.oracle.com
#PROXY_HOST=
#PROXY_PORT is the Port where the proxy server is running
PROXY_PORT=80
#PROXY_PORT=
#NON_PROXY_HOST is the list of non proxy hosts that are divided by a | symbol
#NON_PROXY_HOST=*.oracle.com|*.oraclecorp.com|localhost|127.0.0.1|stbbn10|stbbn10.us.oracle.com
NON_PROXY_HOST=*.oracle.com|*.oraclecorp.com|localhost|127.0.0.1|stbbn10|stbbn10.us.oracle.com|16.157.134.135
When I run the setup.sh , it will report
BUILD FAILED
/opt/software/WL_Installables/build.xml:131: Traceback (innermost last):
File "./wl_scripts/bpelDomain.py", line 22, in ?
File "./wl_scripts/createGroupsAndUsers.py", line 4, in ?
weblogic.management.utils.AlreadyExistsException: [Security:090267]Group BpelGroup
Actully ,there is no BpelGroup in Weblogic. Does anybody know how to solve it ?MAke sure you have not set ANY environment variable related to Oracle / BEA / Java / LD_library path. Use the following script to unset / set the initial settings:
#!/bin/sh
unset ORACLE_BASE ORACLE_HOME ORACLE_SID ORACLE_TERM
unset LD_LIBRARY_PATH LD_LIBRARY_PATH_64
unset CLASSPATH JAVA_HOME
export PATH=.:/usr/sbin:/usr/bin:/usr/local/bin:/opt/VRTS/bin
export BEA_HOME=/appl/oracle/products/9.2/weblogic
Marc
http://orasoa.blogspot.com -
How do you get Oracle 8i to work with j2sdkee 1.3 B
I had the j2sdkee1.2.1 working with Oracle 8i and I had the following line in the ~conifg/default.properties files
Here's what worked:
jdbcDatasources=jdbc/EstoreDB|jdbc:oracle:thin:@localhost:1521:ORCL|jdbc/InventoryDB|jdbc:oracle:thin:@localhost:1521:ORCL|jdbc/jcampDB|jdbc:oracle:thin:@localhost:1521:ORCL
In the j2sdkee1.3 beta 2, the resource configuration file format seem to have changed and I am not sure how to get oracle to work. I have tried modifying the new format but it does not seem to work. Can anyone tell me where set drivers for Oracle 8i or any place I can look to figure how to.
jdbcDataSource.5.name=jdbc/Oracle
jdbcDataSource.5.url=jdbc:oracle:thin:rmi:??;create=true
jdbcDriver.0.name=COM.cloudscape.core.RmiJdbcDriver
jdbcXADataSource.0.name=jdbc/XACloudscape
jdbcXADataSource.0.classname=COM.cloudscape.core.RemoteXaDataSource
jdbcXADataSource.0.dbpassword=
jdbcXADataSource.0.dbuser=
jdbcXADataSource.0.prop.createDatabase=create
jdbcXADataSource.0.prop.databaseName=CloudscapeDB
==============
Any pointers on how to get Oracle 8i to work with j2sdkee1.3 b2 will be appreciated. thanks.
--pvtYou are right. It seems the format has changed.
However, now there is and admin tool that comes with J2EE SDK 1.3 Now you don't have to touch the config file by hand.
You can use this tool to get the configuration done.
To add JDBC driver the command is...
j2eeadmin -addJdbcDriver oracle.jdbc.driver.OracleDriver
and to add a data source the command is...
j2eeadmin -addJdbcDatasource jdbc/Oracle jdbc:oracle:thin@rtc:1521:acct
Read details about this and other configuration you can do using this toll in the file %J2EE_HOME%/doc/release/ConfigGuide.html -
Oracle 11gR2 RAC installation with DNS
Dear Guru's,
I want to configure RAC on two node cluster with DNS(For SCAN) in my testing server.
O.S: RHEL5.4(64 bit)
Oracle Version: 11gR2(11.2.0.2)
Note: Am creating nodes in VMware ESXi server.
Just I want to know whether DNS should be configure in any one of those NODES or in separate machine.
Bala :)Hi Bala,
I want to configure my Database with & without DNS. (Will try both installation in different servers)I think, you have already received a link on very good article about Oracle RAC installation without DNS and DHCP (I mean Jeffrey Hunter's article).
There is one more about Oracle RAC installation with DNS and DHCP (http://gjilevski.com/2011/10/05/build-two-node-oracle-rac-11gr2-11-2-0-3-with-gns-dns-dhcp-and-haip/).
And want to know how it forwards the client connection if a node fails.. Can anyone update the URL for this..There are a lot of information about it:
- http://www.oracle.com/technetwork/database/features/oci/taf-10-133239.pdf
- http://docs.oracle.com/cd/E14072_01/java.112/e10589/apxracfan.htm
- http://www.oracle.com/technetwork/database/app-failover-oracle-database-11g-173323.pdf
Very good videos:
- http://www.dsvolk.ru/oracle/racdd4d/demos/video/taf/session/session_viewlet_swf.html
- http://www.dsvolk.ru/oracle/racdd4d/demos/video/taf/select/select_viewlet_swf.html
- http://www.dsvolk.ru/oracle/racdd4d/demos/video/taf/callback/callback_viewlet_swf.html
- http://www.dsvolk.ru/oracle/racdd4d/demos/video/fan/fan_viewlet_swf.html
Hope it helps,
Best regards,
Gena -
Oracle 11gR2 RAC problem with resource state
Hi all,
I installed Oracle 11gR2 grid infrastructure with 2 nodes and I installed DB 11gR2.
S.O: HP-UX
I actived both DB instance in each node.
For an hardware problem node 1 become unstable (continuos auto reboot).
I found that the problem was RAM.
However I note that database resource is in a particular state and i don't able to reset it.
Performing command crsctl status resource ora.orcl.db this is the result
ora.orcl.db
1 OFFLINE UNKNOWN node1 Startup Initiated
2 ONLINE ONLINE node2 Open
That UNKNOWN state is really abstruse.
I tryed to perform crsctl stop resource ora.orcl.db -n node1 and the result is
CRS-2679: Attempting to clean 'ora.orcl.db' on 'node1'
ORA-01034: ORACLE not available
ORA-27101: shared memory realm does not exist
HPUX-ia64 Error: 2: No such file or directory
Process ID: 0
Session ID: 0 Serial number: 0
CRS-2680: Clean of 'ora.orcl.db' on 'node1' failed
CRS-4000: Command Stop failed, or completed with errors.
I tryed to perform crsctl start resource ora.orcl.db -n node1 and the result is
CRS-2662: Resource 'ora.orcl.db' is disabled on server 'node1'
CRS-4000: Command Start failed, or completed with errors.
How do I do to reset that UNKNOWN state?
Thanks in advance.
Bye
AlessandroI tryed srvctl enable instance -d orcl -i ORCL_1
but the results is
srvctl enable instance command is not supported for configuration using server pool.
I tryed to delete service ora.orcl.db and recreate it.
Now I have
NAME=ora.orcl.db
TYPE=ora.database.type
TARGET=ONLINE , ONLINE
STATE=UNKNOWN on node1, OFFLINE
So Targets are both ONLINE, but if I write crsctl start resource ora.orcl.db
the result is
CRS-2679: Attempting to clean 'ora.orcl.db' on 'node1'
CRS-2672: Attempting to start 'ora.orcl.db' on 'node2'
CRS-5003: Invalid attribute value: '' for attribute DB_UNIQUE_NAME
ORA-01034: ORACLE not available
ORA-27101: shared memory realm does not exist
HPUX-ia64 Error: 2: No such file or directory
Process ID: 0
Session ID: 0 Serial number: 0
CRS-2674: Start of 'ora.orcl.db' on 'node2' failed
CRS-2679: Attempting to clean 'ora.orcl.db' on 'node2'
CRS-2681: Clean of 'ora.orcl.db' on 'node2' succeeded
CRS-2632: There are no more servers to try to place resource 'ora.orcl.db' on that would satisfy its placement policy
CRS-2680: Clean of 'ora.orcl.db' on 'node1' failed
CRS-4000: Command Start failed, or completed with errors.
Where DB_UNIQUE_NAME attribute must be set?
Any other suggest?
Thanks in advance.
Regards.
Alessandro
Edited by: Alessandro Zenoni on 21-giu-2010 11.26 -
Oracle package invalidate problem with the jdbcOracleConnectionCacheImpl ()
Hi all,
I am using the OracleConnectionCacheImpl(); to Create the Oracle connection pool (OracleConnectionCacheImpl class)
In my application i am calling the oracle stored procs.
(DB environment :Oracle 9i)
to call those stored proc i used the Prepared statements.
All the requests are calling the same java bean to invoke the same package.
when ever the changes occured in the db level,(it means if that package is invalid. i.e when ever the db refreshes occured), all the requests are geting oracle error.
after the oracle package become valid.. still i am geting the oracle errors.
it should not happen, because stored proc is in valid state.
if we restart our adapter or java service then we are geting the proper responses.
we don't know when the db problems occurs, when it will be solve
can any one help me to make my application stable
kindly help me to get underastand the behaviour of our java code and the jdbc behaviour.
if any one didn't understand the above description i can mail you the code what i am using..
Thanks in advance
RajThotaA regular Oracle database environment comes with several mandatory userids. These include SYS and SYSTEM. SYS 'owns' all details of the database and SYSTEM is the 'super DBA'. These are database userids, not operating system userids.
I suspect the repository wizard wants to access the SYSTEM userid to be able to create a new schema (equivalent to 'database' for other vendors) within the Oracle environment.
In older versions of Oracle, the default SYSTEM password was 'MANAGER'. These days, any security conscious DBA will have changed that quickly, but ... -
Two model projects (1 for Oracle, 1 for SQLServer) with 1 view project?
We are trying to solve the issue of supporting both Oracle and SQLServer backends with our ADF application. We have read many posts and our application is working against Oracle but have some issues with SQLServer. The entities are created as SQL92/Java. Would a better approach be to create separate model projects and then load or build with the appropriate one. Each would have identical naming so the view would work with either. At run time we know which type of db is installed. If this was to work how would we specify one over the other when building/running?
If I am way off on this idea please let me know and we will continue down the current path.
Thank you
RudyHi Shay,
Yes, I have been through that document and done everything except the primary key generation. Our db's do use the Identity/Sequence features for generating primary keys and this cannot be changed due to legacy systems that also access the db. The error I see against SQLServer when performing a Commit after a CreateInsert, Update, or Delete is this:
<LifecycleImpl> <_handleException> ADF_FACES-60098:Faces lifecycle receives unhandled exceptions in phase INVOKE_APPLICATION 5
javax.faces.el.EvaluationException: oracle.jbo.JboException: [oracle.jbo.DMLException: JBO-26080: Error while selecting entity for GetValueRuleEO]
at org.apache.myfaces.trinidadinternal.taglib.util.MethodExpressionMethodBinding.invoke(MethodExpressionMethodBinding.java:58)
at org.apache.myfaces.trinidad.component.UIXComponentBase.broadcastToMethodBinding(UIXComponentBase.java:1256)
at org.apache.myfaces.trinidad.component.UIXCommand.broadcast(UIXCommand.java:183)
at oracle.adf.view.rich.component.fragment.UIXRegion.broadcast(UIXRegion.java:148)
at oracle.adf.view.rich.component.fragment.ContextSwitchingComponent$1.run(ContextSwitchingComponent.java:92)
This happens against multiple entity objects. The entity PK's are defined as oracle.jbo.Domain.DBSequence with Updatable as Never and no Refresh. Is there a way to set the properties of the application model at runtime, possibly within the initialization servlet?
Thank you. -
I am trying to connect oracle develper suit form with oracle 10g database
i am trying to connect oracle develper suit form with oracle 10g database
but when i pass username and password
this message apperars
ORA-12560:TNS:protocol adapter error
every time even i try to connect Report or Designer each time same problem
making no connection .
can any body help can help me to reslove this prblem
Arshad khanDuplicate thread:
Re: connection problem
Maybe you are looking for
-
Script for Making a Field ReadOnly
In Oracle CRM ON DEMAND we have the "Status" dropdown field with value as "Completed" in Activities. I have Configure it in a such a way so that the Subject field becomes read only when the status is set to Completed.How to do that.
-
Class has be instantiated in document class but having issue..HELP
Guys, I am making my way with AS3 in little steps and have hit a road block. This is what I have: I have a document class called "Document Class" I have a custom class called "Game" I have instantiated an object of "Game" class and I am able to trace
-
We downloaded Office2008 update June 13th. Now our Office programs won't open. Is this happening to others? Does anyone know how to fix the problem? This is the message box content we get when trying to open Word: Process: Microsoft Word [309
-
Hi, Can the BR*Tools actually replace all Oracle OMS/RMAN functions? Systemlandscape: NW04s and Oracle 10. Thanks, Galia
-
Hi. I own an iBook G4, 1.33 GHz, Version 10.4.11 and I am trying to figure out the process of what I need to get/purchase to update the computer to the latest update this computer can possibly get. I need to know which software (Leopard, Snow Leopard