Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
http://www.securityfocus.com/bid/4298
http://www.nextgenss.com/papers/hpoas.pdf
http://www.kb.cert.org/vuls/id/977251
http://www.iss.net/security_center/static/8453.php