Security Issue : JVMInfo.jsp Dsiplays To Much Information
(Doc ID 1641569.1)
Last updated on DECEMBER 04, 2019
Applies to:
Oracle Utilities Customer Care and Billing - Version 2.3.1 and laterInformation in this document applies to any platform.
Goal
The page JVMInfo.jsp can be called by anybody without any autentication and shows a lot of technical information.
This type of information could help a hacker in infiltrating the application.
Is it possible to disable this page or restrict its access ?
Solution
To view full details, sign in with your My Oracle Support account. |
|
Don't have a My Oracle Support account? Click to get started! |
In this Document
Goal |
Solution |