CVE-2002-2153: High severity Oracle Application Server vulnerability
Published Dec 31, 2002
·Updated
Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code.
Affected Software
2 affected components
Oracle Application Server=4.0.8.2
Oracle Application Server=4.0.8
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Nov 17, 2005
CVE Published
via MITRE·02:17 AM
Data Sourced
via MITRE·02:17 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2153?
CVE-2002-2153 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code on the affected systems.
2
How do I fix CVE-2002-2153?
To fix CVE-2002-2153, it is recommended to upgrade to a patched version of Oracle Application Server, specifically versions later than 4.0.8.2.
3
Which versions of Oracle Application Server are affected by CVE-2002-2153?
CVE-2002-2153 affects Oracle Application Server versions 4.0.8 and 4.0.8.2.
4
Can CVE-2002-2153 be exploited remotely?
Yes, CVE-2002-2153 can be exploited remotely without authentication, putting systems at high risk.
5
What type of vulnerability is CVE-2002-2153?
CVE-2002-2153 is a format string vulnerability found in the administrative pages of the PL/SQL module.