5
CVSSv2

CVE-2002-0565

Published: 03/07/2002 Updated: 19/12/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote malicious users to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle application server web cache 2.0.0.3

oracle oracle9i 9.0

oracle oracle9i 9.0.1

oracle application server web cache 2.0.0.0

oracle application server web cache 2.0.0.1

oracle application server web cache 2.0.0.2

oracle application server 1.0.2