CVE-2002-1025: Medium severity Macromedia JRun vulnerability
Published Oct 4, 2002
·Updated
JRun 3.0 through 4.0 allows remote attackers to read JSP source code via an encoded null byte in an HTTP GET request, which causes the server to send the .JSP file unparsed.
Affected Software
3 affected components
Macromedia JRun=3.0
Macromedia JRun=3.1
Macromedia JRun=4.0
Remediation
Patch Available
Patch Available
Event History
Oct 4, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-1025?
CVE-2002-1025 is considered a medium severity vulnerability due to its potential to expose sensitive JSP source code.
2
How do I fix CVE-2002-1025?
To fix CVE-2002-1025, it is recommended to upgrade to a version of JRun that is not affected, such as any version later than 4.0.
3
What versions are affected by CVE-2002-1025?
CVE-2002-1025 affects Macromedia JRun versions 3.0, 3.1, and 4.0.
4
Can CVE-2002-1025 be exploited remotely?
Yes, CVE-2002-1025 can be exploited remotely by attackers which allows them to read JSP files.
5
What type of attacks does CVE-2002-1025 enable?
CVE-2002-1025 enables attackers to access unparsed JSP source code, potentially revealing sensitive information.