First published: Tue Jun 11 2002(Updated: )
The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle9i | =9.0.1 | |
Oracle Application Server Web Cache | =2.0.0.2 | |
Oracle Oracle9i | =9.0 | |
Oracle Application Server Web Cache | =2.0.0.1 | |
Oracle Application Server Web Cache | =2.0.0.0 | |
Oracle Application Server | =1.0.2 | |
Oracle Application Server Web Cache | =2.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0562 has a medium severity rating due to the potential exposure of sensitive information.
To fix CVE-2002-0562, you should apply the latest security patches for Oracle 9i Application Server and ensure proper configuration to restrict access to globals.jsa.
CVE-2002-0562 affects Oracle 9i Application Server 1.0.2.x and various versions of Oracle Application Server Web Cache.
CVE-2002-0562 can expose sensitive information including usernames and passwords through direct HTTP access.
While CVE-2002-0562 originated in older versions, organizations using obsolete Oracle products may still face risks associated with this vulnerability.