PT-2002-1615 · Oracle · Oracle9Ias

Publicado

2002-06-11

·

Atualizado

2017-12-19

·

CVE-2002-0565

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle 9iAS version 1.0.2.x
Description The issue allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to pages. This is because JSP files in the pages directory are compiled with world-readable permissions under the web root.
Recommendations For Oracle 9iAS version 1.0.2.x, restrict access to the pages directory to prevent remote attackers from obtaining sensitive information. Consider changing the permissions of the compiled JSP files to prevent world-readable access.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0565

Produtos afetados

Oracle9Ias