VYPR
Unrated severityNVD Advisory· Published Jul 23, 1997· Updated Apr 16, 2026

CVE-1999-1068

CVE-1999-1068

Description

Oracle Webserver 2.1 crashes when a long HTTP GET request is sent to a PL/SQL stored procedure endpoint, causing denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Oracle Webserver 2.1 crashes when a long HTTP GET request is sent to a PL/SQL stored procedure endpoint, causing denial of service.

Vulnerability

Oracle Webserver 2.1, when configured to serve PL/SQL stored procedures (commonly at endpoints like /ows-bin/), suffers from a denial-of-service vulnerability. A remote attacker can send an HTTP GET request with a long query string parameter (e.g. 2600 'a' characters) to the PL/SQL endpoint, causing the server to crash silently. Version 2.0 does not exhibit this behavior [1].

Exploitation

No authentication or special privileges are required; the attacker only needs network access to the target webserver. Using a combination of Perl and NetCat (or any other HTTP client), the attacker sends an HTTP GET request to the PL/SQL stored procedure path with a parameter containing an overly long value. The server processes the request and crashes immediately, with no log entry generated [1].

Impact

A successful attack causes the Oracle Webserver 2.1 process to terminate, resulting in a denial of service. The server becomes unavailable to legitimate users until manually restarted. There is no indication of the crash in the server logs, hindering detection [1].

Mitigation

No official patch or fix is documented in the available references [1]. As of the publication date (July 1997), the vendor had not released a solution. Administrators are advised to upgrade to a later, unaffected version (e.g., Oracle Webserver 2.0 did not exhibit the crash) or implement network-level filtering to block excessively long request URIs.

AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.