s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-1999-1125 high

📛 Threat Title

CVE-1999-1125

Category: vulnerability Published: Source updated: First seen: Last updated: Source: NVD Recent CVEs

Description

Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (2)

  • cve@mitre.org NVD Recent CVEs
  • NVD detail: CVE-1999-1125 NVD Recent CVEs

    Oracle Webserver 2.1 and earlier runs setuid root, but the configuration file is owned by the oracle account, which allows any local or remote attacker who obtains access to the oracle account to gain privileges or modify arbitrary files by modifying the configuration file.

Remediations (10)

  • web:cybersecuritynews.com

    Microsoft rolled out its November 2025 Patch Tuesday security updates today, addressing 63 vulnerabilities across its product and service ecosystem.

  • web:github.com

    Patch for Windows 9x to fix CPU issues. Contribute to JHRobotics/patcher9x development by creating an account on GitHub.

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:support.esri.com

    Refer to the Issues Addressed with this Patch section for details about BUG-000171492. The new patch when shown as available in the ArcGIS Enterprise Patch Notification tool, is listed as ArcGIS Server Security 2025 Update 1 Patch with a release date of April 17, 2025; once installed, it is listed as ArcGIS Server Security 2025 Update 1 Patch B.

  • web:www.bleepingcomputer.com

    Today is Microsoft's November 2025 Patch Tuesday, which includes security updates for 63 flaws, including one actively exploited zero-day vulnerability.

  • web:www.cisa.gov

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework.

  • web:www.crowdstrike.com

    Microsoft has released security updates for 63 vulnerabilities, including 1 zero-day and 4 critical vulnerabilities, in its November 2025 Patch Tuesday rollout.

  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

  • web:www.rapid7.com

    Microsoft is publishing 66 new vulnerabilities today, which is far fewer than we've come to expect in recent months. However, the lone zero-day vulnerability this month demands attention.

  • web:www.virustotal.com

    VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.