CVE-2002-0559: Buffer Overflow
Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a long Access Descriptor (DAD) password in the addadd form, or (5) a long cache directory name.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0559?
CVE-2002-0559 is rated as a critical vulnerability due to its potential for remote code execution and denial of service.
How do I fix CVE-2002-0559?
To fix CVE-2002-0559, update your Oracle 9i Application Server and affected components to the latest patched version.
What versions of software are affected by CVE-2002-0559?
CVE-2002-0559 affects Oracle 9i Application Server 1.0.2.x, Oracle 9i version 9.0.1, and various versions of Oracle Application Server Web Cache.
What are the potential impacts of exploiting CVE-2002-0559?
Exploiting CVE-2002-0559 can lead to a denial of service or allow remote attackers to execute arbitrary code on the server.
Is there a workaround for CVE-2002-0559 if I cannot apply a patch?
As a temporary workaround for CVE-2002-0559, restrict access to the impacted services and monitor for unusual traffic patterns.