PT-2002-1615 · Oracle · Oracle9Ias
Published
2002-06-11
·
Updated
2017-12-19
·
CVE-2002-0565
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle 9iAS version 1.0.2.x
Description
The issue allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to
pages. This is because JSP files in the pages directory are compiled with world-readable permissions under the web root.Recommendations
For Oracle 9iAS version 1.0.2.x, restrict access to the
pages directory to prevent remote attackers from obtaining sensitive information. Consider changing the permissions of the compiled JSP files to prevent world-readable access.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle9Ias