PT-2002-1612 · Oracle · Oracle 9I Application Server
Published
2002-06-11
·
Updated
2016-10-18
·
CVE-2002-0562
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle 9i Application Server version 1.0.2.x
Description
The default configuration of the software stores globals.jsa under the web root, allowing remote attackers to gain sensitive information, including usernames and passwords, via a direct HTTP request to globals.jsa.
Recommendations
For Oracle 9i Application Server version 1.0.2.x, consider restricting access to the globals.jsa file to prevent unauthorized disclosure of sensitive information.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle 9I Application Server