CVE-2002-1089: Medium severity Oracle Application Server vulnerability
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1089?
CVE-2002-1089 has a moderate severity level due to the potential exposure of sensitive system information.
How do I fix CVE-2002-1089?
To mitigate CVE-2002-1089, it's recommended to upgrade to a patched version of Oracle Reports Server or to configure access controls appropriately.
What systems are affected by CVE-2002-1089?
CVE-2002-1089 affects Oracle Reports Server version 6.0.8.19 and earlier, as well as Oracle Application Server version 9.0.2.
Can CVE-2002-1089 lead to further attacks?
Yes, the information leaked by CVE-2002-1089 could enable attackers to craft additional attacks against the affected systems.
Is CVE-2002-1089 still relevant today?
While CVE-2002-1089 is an older vulnerability, systems using the affected versions remain at risk if they have not been updated.