PT-2002-1611 · Oracle · Oracle 9I Application Server

Published

2002-06-11

·

Updated

2016-10-18

·

CVE-2002-0561

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oracle 9i Application Server versions 1.0.2.x
Description The default configuration of the PL/SQL Gateway web administration interface uses null authentication, allowing remote attackers to gain privileges and modify DAD settings.
Recommendations For Oracle 9i Application Server versions 1.0.2.x, consider configuring the PL/SQL Gateway web administration interface to use proper authentication to prevent unauthorized access and modification of DAD settings.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0561

Affected Products

Oracle 9I Application Server