First published: Tue Jun 11 2002(Updated: )
Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Oracle9i | =9.0.1 | |
Oracle Application Server Web Cache | =2.0.0.2 | |
Oracle Oracle9i | =9.0 | |
Oracle Application Server Web Cache | =2.0.0.1 | |
Oracle Application Server Web Cache | =2.0.0.0 | |
Oracle Application Server | =1.0.2 | |
Oracle Application Server Web Cache | =2.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0565 has a medium severity, as it allows remote attackers to access sensitive information.
To fix CVE-2002-0565, restrict the permissions of the _pages directory to prevent world-readable access.
CVE-2002-0565 affects Oracle products including Oracle 9iAS 1.0.2.x and some specific versions of Application Server Web Cache.
CVE-2002-0565 can expose sensitive information such as usernames and passwords embedded in JSP files.
While CVE-2002-0565 is an older vulnerability, it remains a threat for systems that have not been updated or configured correctly.