CVE-2002-0103
published 2002-03-25CVE-2002-0103: An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain…
PriorityP414medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.61%
45.3th percentile
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server_web_cache | — | — |
| oracle | application_server_web_cache | — | — |
| oracle | application_server_web_cache | — | — |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f3jp-grwv-3275: An installer program for Oracle9iAS Web Cache 2
ghsa_unreviewed·2022-04-30
CVE-2002-0103 [MEDIUM] GHSA-f3jp-grwv-3275: An installer program for Oracle9iAS Web Cache 2
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
Red Hat
krb5: UDP ping-pong flaw in kpasswd
vendor_redhat·2002-06-16·CVSS 5.0
CVE-2002-2443 [MEDIUM] krb5: UDP ping-pong flaw in kpasswd
krb5: UDP ping-pong flaw in kpasswd
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=101041510727937&w=2http://otn.oracle.com/deploy/security/pdf/webcache2.pdfhttp://www.iss.net/security_center/static/7766.phphttp://www.iss.net/security_center/static/7768.phphttp://www.securityfocus.com/bid/3761http://www.securityfocus.com/bid/3764http://marc.info/?l=bugtraq&m=101041510727937&w=2http://otn.oracle.com/deploy/security/pdf/webcache2.pdfhttp://www.iss.net/security_center/static/7766.phphttp://www.iss.net/security_center/static/7768.phphttp://www.securityfocus.com/bid/3761http://www.securityfocus.com/bid/3764
2002-03-25
Published