{"api_version":"1","generated_at":"2026-07-23T04:19:59+00:00","cve":"CVE-2002-1640","urls":{"html":"https://cve.report/CVE-2002-1640","api":"https://cve.report/api/cve/CVE-2002-1640.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-1640","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-1640"},"summary":{"title":"CVE-2002-1640","description":"Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-04-01 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/4430","name":"http://www.securityfocus.com/bid/4430","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"Oracle Configurator Text Features User-Embedded Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8781","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8781","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4436","name":"http://www.securityfocus.com/bid/4436","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry","Vendor Advisory"],"title":"504 Gateway Time-out","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8780","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8780","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html","name":"http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Oracle Configurator Vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://securitytracker.com/id?1003967","name":"http://securitytracker.com/id?1003967","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - Oracle Configurator Filtering Holes Let Remote Users Conduct Cross-Site Scripting Attacks Against Configurator Users to Obtain Sensitive Information","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-1640","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-1640","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"1640","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"configurator","cpe6":"11i","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1640","vulnerable":"1","versionEndIncluding":"11.5.6.16.52","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"configurator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"1640","vulnerable":"1","versionEndIncluding":"11.5.7.17.31","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"configurator","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:34:55.158Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"oracle-configurator-uiservlet-css(8781)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8781"},{"name":"1003967","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1003967"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html"},{"name":"4430","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4430"},{"name":"4436","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4436"},{"name":"oracle-configurator-dhtml-css(8780)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8780"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-04-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"oracle-configurator-uiservlet-css(8781)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8781"},{"name":"1003967","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1003967"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html"},{"name":"4430","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4430"},{"name":"4436","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4436"},{"name":"oracle-configurator-dhtml-css(8780)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8780"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-1640","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"oracle-configurator-uiservlet-css(8781)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8781"},{"name":"1003967","refsource":"SECTRACK","url":"http://securitytracker.com/id?1003967"},{"name":"http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html","refsource":"CONFIRM","url":"http://www.oracle.com/technology//deploy/security/htdocs/oconfigvul.html"},{"name":"4430","refsource":"BID","url":"http://www.securityfocus.com/bid/4430"},{"name":"4436","refsource":"BID","url":"http://www.securityfocus.com/bid/4436"},{"name":"oracle-configurator-dhtml-css(8780)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/8780"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-1640","datePublished":"2005-03-28T05:00:00.000Z","dateReserved":"2005-03-28T00:00:00.000Z","dateUpdated":"2024-08-08T03:34:55.158Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-04-01 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:*","versionStartIncluding":"11.5.6.0.0","versionEndIncluding":"11.5.6.16.52","matchCriteriaId":"7DB49A7C-58C0-43DE-86A6-28FB54E49D6F"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:configurator:*:*:*:*:*:*:*:*","versionStartIncluding":"11.5.7.0.0","versionEndIncluding":"11.5.7.17.31","matchCriteriaId":"DDE2F798-C8C9-4013-A658-6FCE74B12434"},{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:configurator:11i:*:*:*:*:*:*:*","matchCriteriaId":"1E3B24CB-5198-4172-AF66-8B210BB14FDA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"1640","Ordinal":"1","Title":"CVE-2002-1640","CVE":"CVE-2002-1640","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"1640","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Oracle Configurator before 11.5.7.17.32 and 11.5.6.16.53 allows remote attackers to inject arbitrary web script or HTML via (1) Text Features in the DHTML UI or (2) the test parameter to the oracle.apps.cz.servlet.UiServlet servlet.","Type":"Description","Title":"CVE-2002-1640"},{"CveYear":"2002","CveId":"1640","Ordinal":"2","NoteData":"2005-03-28","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"1640","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}