PT-2002-1612 · Oracle · Oracle 9I Application Server

Published

2002-06-11

·

Updated

2016-10-18

·

CVE-2002-0562

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle 9i Application Server version 1.0.2.x
Description The default configuration of the software stores globals.jsa under the web root, allowing remote attackers to gain sensitive information, including usernames and passwords, via a direct HTTP request to globals.jsa.
Recommendations For Oracle 9i Application Server version 1.0.2.x, consider restricting access to the globals.jsa file to prevent unauthorized disclosure of sensitive information.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0562

Affected Products

Oracle 9I Application Server