CVE-2002-0564: High severity Oracle Application Server vulnerability
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0564?
CVE-2002-0564 is classified as a high severity vulnerability due to its ability to allow remote attackers to bypass authentication.
How do I fix CVE-2002-0564?
To fix CVE-2002-0564, ensure that your Oracle 9i Application Server and all related components are updated to the latest security patches provided by Oracle.
What are the affected versions for CVE-2002-0564?
CVE-2002-0564 affects Oracle Application Server versions 1.0.2.x and Oracle Web Cache versions 2.0.0.x.
What types of attacks can exploit CVE-2002-0564?
CVE-2002-0564 can be exploited by attackers to gain unauthorized access to sensitive data by modifying the URL to reference a Database Access Descriptor with valid credentials.
Is there any workaround for CVE-2002-0564?
Disabling or restricting access to the vulnerable Database Access Descriptor can act as a temporary workaround for CVE-2002-0564 until a patch is successfully implemented.