PT-2002-1615 · Oracle · Oracle9Ias

Published

2002-06-11

·

Updated

2017-12-19

·

CVE-2002-0565

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle 9iAS version 1.0.2.x
Description The issue allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to pages. This is because JSP files in the pages directory are compiled with world-readable permissions under the web root.
Recommendations For Oracle 9iAS version 1.0.2.x, restrict access to the pages directory to prevent remote attackers from obtaining sensitive information. Consider changing the permissions of the compiled JSP files to prevent world-readable access.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0565

Affected Products

Oracle9Ias