PT-2002-1611 · Oracle · Oracle 9I Application Server
Published
2002-06-11
·
Updated
2016-10-18
·
CVE-2002-0561
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle 9i Application Server versions 1.0.2.x
Description
The default configuration of the PL/SQL Gateway web administration interface uses null authentication, allowing remote attackers to gain privileges and modify DAD settings.
Recommendations
For Oracle 9i Application Server versions 1.0.2.x, consider configuring the PL/SQL Gateway web administration interface to use proper authentication to prevent unauthorized access and modification of DAD settings.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle 9I Application Server