{"api_version":"1","generated_at":"2026-07-23T03:39:51+00:00","cve":"CVE-2002-0568","urls":{"html":"https://cve.report/CVE-2002-0568","api":"https://cve.report/api/cve/CVE-2002-0568.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0568","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0568"},"summary":{"title":"CVE-2002-0568","description":"Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-07-03 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.cert.org/advisories/CA-2002-08.html","name":"http://www.cert.org/advisories/CA-2002-08.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"CERT Advisory CA-2002-08 Multiple Vulnerabilities in Oracle Servers","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/476619","name":"http://www.kb.cert.org/vuls/id/476619","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"CERT/CC Vulnerability Note VU#476619","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=101301813117562&w=2","name":"http://marc.info/?l=bugtraq&m=101301813117562&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Hackproofing Oracle Application Server paper' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.nextgenss.com/papers/hpoas.pdf","name":"http://www.nextgenss.com/papers/hpoas.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"nextgenss.com -&nbspThis website is for sale! -&nbspnextgenss Resources and Information.","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4290","name":"http://www.securityfocus.com/bid/4290","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Oracle 9i Default Configuration File Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0568","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0568","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"568","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"application_server","cpe6":"1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"568","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"oracle8i","cpe6":"8.1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"568","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"oracle8i","cpe6":"8.1.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"568","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"oracle9i","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"568","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"oracle9i","cpe6":"9.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:56:38.255Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020206 Hackproofing Oracle Application Server paper","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=101301813117562&w=2"},{"name":"CA-2002-08","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.cert.org/advisories/CA-2002-08.html"},{"name":"4290","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4290"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.nextgenss.com/papers/hpoas.pdf"},{"name":"VU#476619","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/476619"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-02-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020206 Hackproofing Oracle Application Server paper","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=101301813117562&w=2"},{"name":"CA-2002-08","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.cert.org/advisories/CA-2002-08.html"},{"name":"4290","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4290"},{"tags":["x_refsource_MISC"],"url":"http://www.nextgenss.com/papers/hpoas.pdf"},{"name":"VU#476619","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/476619"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0568","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020206 Hackproofing Oracle Application Server paper","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=101301813117562&w=2"},{"name":"CA-2002-08","refsource":"CERT","url":"http://www.cert.org/advisories/CA-2002-08.html"},{"name":"4290","refsource":"BID","url":"http://www.securityfocus.com/bid/4290"},{"name":"http://www.nextgenss.com/papers/hpoas.pdf","refsource":"MISC","url":"http://www.nextgenss.com/papers/hpoas.pdf"},{"name":"VU#476619","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/476619"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0568","datePublished":"2002-06-11T04:00:00.000Z","dateReserved":"2002-06-07T00:00:00.000Z","dateUpdated":"2024-08-08T02:56:38.255Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-07-03 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"CC62E1B2-6964-4459-A1EF-A6A087C2960F"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:oracle8i:8.1.7:*:*:*:*:*:*:*","matchCriteriaId":"5E0E5C6A-FFEA-4855-AE5D-65806B6AFA59"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:oracle8i:8.1.7.1:*:*:*:*:*:*:*","matchCriteriaId":"F2607015-B358-4963-968C-777E2AE9650D"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:oracle9i:9.0:*:*:*:*:*:*:*","matchCriteriaId":"2C2720EA-55FB-40B1-BE58-3E16628DA248"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:oracle9i:9.0.1:*:*:*:*:*:*:*","matchCriteriaId":"D9BB176D-7A94-4A91-89FC-9971E19FF7C6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"568","Ordinal":"1","Title":"CVE-2002-0568","CVE":"CVE-2002-0568","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"568","Ordinal":"1","NoteData":"Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.","Type":"Description","Title":"CVE-2002-0568"},{"CveYear":"2002","CveId":"568","Ordinal":"2","NoteData":"2002-06-11","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"568","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}