CVE-2002-0562
Summary
| CVE | CVE-2002-0562 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-07-03 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Application Server | 1.0.2 | All | All | All |
| Application | Oracle | Application Server Web Cache | 2.0.0.0 | All | All | All |
| Application | Oracle | Application Server Web Cache | 2.0.0.1 | All | All | All |
| Application | Oracle | Application Server Web Cache | 2.0.0.2 | All | All | All |
| Application | Oracle | Application Server Web Cache | 2.0.0.3 | All | All | All |
| Application | Oracle | Oracle9i | 9.0 | All | All | All |
| Application | Oracle | Oracle9i | 9.0.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle 9IAS OracleJSP Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| CERT Advisory CA-2002-08 Multiple Vulnerabilities in Oracle Servers | af854a3a-2127-422b-91ae-364da2661108 | www.cert.org | Patch, Third Party Advisory, US Government Resource |
| CERT/CC Vulnerability Note VU#698467 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Technical Resources | Oracle | af854a3a-2127-422b-91ae-364da2661108 | otn.oracle.com | Patch, Vendor Advisory |
| 'JSP translation file access under Oracle 9iAS' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.