First published: Tue Jun 11 2002(Updated: )
Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle9i | =9.0.1 | |
Oracle Application Server Web Cache | =2.0.0.2 | |
Oracle Oracle9i | =9.0 | |
Oracle Application Server Web Cache | =2.0.0.1 | |
Oracle Application Server Web Cache | =2.0.0.0 | |
Oracle Application Server | =1.0.2 | |
Oracle Application Server Web Cache | =2.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.