PT-2002-1612 · Oracle · Oracle 9I Application Server
Publicado
2002-06-11
·
Atualizado
2016-10-18
·
CVE-2002-0562
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle 9i Application Server version 1.0.2.x
Description
The default configuration of the software stores globals.jsa under the web root, allowing remote attackers to gain sensitive information, including usernames and passwords, via a direct HTTP request to globals.jsa.
Recommendations
For Oracle 9i Application Server version 1.0.2.x, consider restricting access to the globals.jsa file to prevent unauthorized disclosure of sensitive information.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle 9I Application Server