PT-2002-1613 · Oracle · Oracle 9I Application Server
Published
2002-06-11
·
Updated
2017-07-11
·
CVE-2002-0563
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle 9i Application Server version 1.0.2.x
Description
The default configuration of the server allows remote anonymous users to access sensitive services without authentication. This includes access to Dynamic Monitoring Services such as
dms0, dms/DMSDump, servlet/DMSDump, servlet/Spy, soap/servlet/Spy, and dms/AggreSpy. Additionally, Oracle Java Process Manager services like oprocmgr-status and oprocmgr-service can be accessed, which can be used to control Java processes.Recommendations
For Oracle 9i Application Server version 1.0.2.x, consider reconfiguring the server to require authentication for access to sensitive services, including Dynamic Monitoring Services and Oracle Java Process Manager. As a temporary workaround, restrict access to these services to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle 9I Application Server