CVE-2002-2345: High severity Oracle Application Server vulnerability
Published Dec 31, 2002
·Updated
Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.
Affected Software
1 affected component
Oracle Application Server=9.0.2
Event History
Dec 31, 2002
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 29, 2007
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-2345?
CVE-2002-2345 is a high-severity vulnerability due to the storage of sensitive passwords in plaintext.
2
How do I fix CVE-2002-2345?
To mitigate CVE-2002-2345, you should upgrade to a newer version of Oracle Application Server that does not store passwords in plaintext.
3
Who is affected by CVE-2002-2345?
CVE-2002-2345 affects installations of Oracle Application Server 9.0.2.
4
What could an attacker do with CVE-2002-2345?
An attacker could exploit CVE-2002-2345 to gain unauthorized access to the web cache administrator interface.
5
Is CVE-2002-2345 a local or remote vulnerability?
CVE-2002-2345 is a remote vulnerability that allows attackers to access sensitive information from a distance.