First published: Mon Apr 01 2002(Updated: )
Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to obtain sensitive information via a request to the oracle.apps.cz.servlet.UiServlet servlet with the test parameter set to "version" or "host".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Configurator | =11i | |
Oracle Configurator | >=11.5.7.0.0<=11.5.7.17.31 | |
Oracle Configurator | >=11.5.6.0.0<=11.5.6.16.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1639 is categorized as a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2002-1639, upgrade Oracle Configurator to version 11.5.7.17.32 or 11.5.6.16.54 or higher.
CVE-2002-1639 affects users of Oracle Configurator versions prior to 11.5.7.17.32 and 11.5.6.16.53.
CVE-2002-1639 can potentially expose sensitive configuration information through manipulated requests.
Yes, CVE-2002-1639 is a remote vulnerability that allows attackers to access sensitive information without prior authentication.