got 0day?
  • Home
Subscribe
Tagged

Oracle

A collection of 1 post

The perfect SSO account takeover with Oracle OAM (CVE-2018-2739)
Oracle

The perfect SSO account takeover with Oracle OAM (CVE-2018-2739)

TL;DR This weakness allows us to bypass the URL filtering on the RH parameter which could be used to hijack the session of any user when following a particularly crafted link. In summary, phishing heaven ! Intro Oracle Authentication Manager (OAM) 10G or OAM 11g with Webgates 10g parse SSO

  • ⠝⠁⠃⠑⠑⠇ ⠁⠓⠍⠑⠙ (Nabeel Ahmed)
⠝⠁⠃⠑⠑⠇ ⠁⠓⠍⠑⠙ (Nabeel Ahmed) Apr 17, 2018 • 4 min read
got 0day? © 2026
Powered by Ghost