CVE-1999-1125
high
📛 Threat Title
CVE-1999-1125
Description
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
- cve@mitre.org NVD Recent CVEs
-
NVD detail: CVE-1999-1125
NVD Recent CVEs
Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.
Remediations (10)
-
web:cybersecuritynews.com
Microsoft rolled out its November 2025 Patch Tuesday security updates today, addressing 63 vulnerabilities across its product and service ecosystem.
-
web:github.com
Patch for Windows 9x to fix CPU issues. Contribute to JHRobotics/patcher9x development by creating an account on GitHub.
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:support.esri.com
Refer to the Issues Addressed with this Patch section for details about BUG-000171492. The new patch when shown as available in the ArcGIS Enterprise Patch Notification tool, is listed as ArcGIS Server Security 2025 Update 1 Patch with a release date of April 17, 2025; once installed, it is listed as ArcGIS Server Security 2025 Update 1 Patch B.
-
web:www.bleepingcomputer.com
Today is Microsoft's November 2025 Patch Tuesday, which includes security updates for 63 flaws, including one actively exploited zero-day vulnerability.
-
web:www.cisa.gov
For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.
-
web:www.crowdstrike.com
Microsoft has released security updates for 63 vulnerabilities, including 1 zero-day and 4 critical vulnerabilities, in its November 2025 Patch Tuesday rollout.
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.rapid7.com
Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.
-
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.