CVE-2002-2186: Medium severity Macromedia JRun vulnerability
Published Dec 31, 2002
·Updated
Macromedia JRun 3.0, 3.1, and 4.0 allow remote attackers to view the source code of .JSP files via Unicode encoded character values in a URL.
Affected Software
3 affected components
Macromedia JRun=3.1
Macromedia JRun=3.0
Macromedia JRun=4.0
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityAffected Software
Nov 16, 2005
CVE Published
via MITRE·09:17 PM
Data Sourced
via MITRE·09:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2186?
CVE-2002-2186 has a moderate severity rating as it allows unauthorized access to the source code of JSP files.
2
How do I fix CVE-2002-2186?
To fix CVE-2002-2186, upgrade to a newer version of Macromedia JRun that does not have this vulnerability.
3
What versions of Macromedia JRun are affected by CVE-2002-2186?
CVE-2002-2186 affects Macromedia JRun versions 3.0, 3.1, and 4.0.
4
What type of attack does CVE-2002-2186 enable?
CVE-2002-2186 enables remote attackers to view sensitive source code through crafted URLs.
5
Is CVE-2002-2186 still a relevant vulnerability today?
While CVE-2002-2186 is an older vulnerability, it remains relevant for systems that still use affected versions of JRun.