PT-2002-1613 · Oracle · Oracle 9I Application Server

Publicado

2002-06-11

·

Atualizado

2017-07-11

·

CVE-2002-0563

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle 9i Application Server version 1.0.2.x
Description The default configuration of the server allows remote anonymous users to access sensitive services without authentication. This includes access to Dynamic Monitoring Services such as dms0, dms/DMSDump, servlet/DMSDump, servlet/Spy, soap/servlet/Spy, and dms/AggreSpy. Additionally, Oracle Java Process Manager services like oprocmgr-status and oprocmgr-service can be accessed, which can be used to control Java processes.
Recommendations For Oracle 9i Application Server version 1.0.2.x, consider reconfiguring the server to require authentication for access to sensitive services, including Dynamic Monitoring Services and Oracle Java Process Manager. As a temporary workaround, restrict access to these services to minimize the risk of exploitation.

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2002-0563

Produtos afetados

Oracle 9I Application Server