PT-2002-1615 · Oracle · Oracle9Ias
Publicado
2002-06-11
·
Atualizado
2017-12-19
·
CVE-2002-0565
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle 9iAS version 1.0.2.x
Description
The issue allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to
pages. This is because JSP files in the pages directory are compiled with world-readable permissions under the web root.Recommendations
For Oracle 9iAS version 1.0.2.x, restrict access to the
pages directory to prevent remote attackers from obtaining sensitive information. Consider changing the permissions of the compiled JSP files to prevent world-readable access.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle9Ias