First published: Tue Dec 31 2002(Updated: )
Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Application Server | =9.0.2.0.0 | |
Oracle Application Server | =9.0.2.0.1 | |
Oracle Application Server | =1.0.2.1s | |
Oracle Application Server | =1.0.2.2 | |
Oracle Application Server | =1.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1632 has a medium severity level due to its potential to expose sensitive information.
To address CVE-2002-1632, remove or restrict access to the sample pages such as info.jsp, printenv, echo, and echo2.
CVE-2002-1632 can expose environment variables and other sensitive information to remote attackers.
Yes, CVE-2002-1632 remains a threat for users who are still running affected versions of Oracle 9i Application Server.
CVE-2002-1632 affects multiple versions including Oracle Application Server 9.0.2.0.0, 9.0.2.0.1, and 1.0.2 versions.