First published: Fri Mar 15 2002(Updated: )
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server Web Cache | =2.0.0.2 | |
Oracle Application Server Web Cache | =2.0.0.1 | |
Oracle Application Server Web Cache | =2.0.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0103 is classified as a medium severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2002-0103, adjust the permissions of the executable and configuration files to restrict access.
CVE-2002-0103 affects Oracle9iAS Web Cache versions 2.0.0.0, 2.0.0.1, and 2.0.0.2.
CVE-2002-0103 can be exploited by local users to gain higher privileges, potentially allowing unauthorized access to sensitive data.
A potential workaround for CVE-2002-0103 is to ensure that only trusted users have access to the system where Oracle9iAS Web Cache is installed.