7.5
CVSSv2

CVE-2002-0564

Published: 03/07/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote malicious users to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle oracle8i 8.1.7

oracle oracle8i 8.1.7.1

oracle application server 1.0.2

oracle oracle9i 9.0

oracle oracle9i 9.0.1

oracle application server web cache 2.0.0.2

oracle application server web cache 2.0.0.3

oracle application server web cache 2.0.0.0

oracle application server web cache 2.0.0.1