First published: Thu May 03 2001(Updated: )
Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <<ALL FILES>> FilePermission.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server | =release_1.0.2.0.1 | |
Oracle 8i | =8.1.7_r3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-0326 is considered a medium severity vulnerability due to its potential for unauthorized file access.
To fix CVE-2001-0326, reconfigure the server to restrict the use of <<ALL FILES>> FilePermission.
CVE-2001-0326 affects users of Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1.
CVE-2001-0326 can be exploited by remote attackers to read sensitive files on the server.
CVE-2001-0326 was discovered in early 2001, highlighting a vulnerability in older versions of Oracle software.