CVE-2002-0563
published 2002-07-03CVE-2002-0563: The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including…
PriorityP337medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
51.13%
98.8th percentile
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server_web_cache | — | — |
| oracle | application_server_web_cache | — | — |
| oracle | application_server_web_cache | — | — |
| oracle | application_server_web_cache | — | — |
| oracle | oracle8i | — | — |
| oracle | oracle8i | — | — |
| oracle | oracle9i | — | — |
| oracle | oracle9i | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-gmx4-93pr-r35c: Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2007-1609 [MEDIUM] GHSA-gmx4-93pr-r35c: Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.
GHSA
GHSA-c5h7-mjwp-4pvr: The default configuration of Oracle 9i Application Server 1
ghsa_unreviewed·2022-04-30
CVE-2002-0563 [MEDIUM] CWE-287 GHSA-c5h7-mjwp-4pvr: The default configuration of Oracle 9i Application Server 1
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=101301813117562&w=2http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdfhttp://securitytracker.com/id?1009167http://www.appsecinc.com/Policy/PolicyCheck7024.htmlhttp://www.cert.org/advisories/CA-2002-08.htmlhttp://www.kb.cert.org/vuls/id/168795http://www.nextgenss.com/papers/hpoas.pdfhttp://www.osvdb.org/13152http://www.osvdb.org/705http://www.securityfocus.com/bid/4293https://exchange.xforce.ibmcloud.com/vulnerabilities/8455http://marc.info/?l=bugtraq&m=101301813117562&w=2http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdfhttp://securitytracker.com/id?1009167http://www.appsecinc.com/Policy/PolicyCheck7024.htmlhttp://www.cert.org/advisories/CA-2002-08.htmlhttp://www.kb.cert.org/vuls/id/168795http://www.nextgenss.com/papers/hpoas.pdfhttp://www.osvdb.org/13152http://www.osvdb.org/705http://www.securityfocus.com/bid/4293https://exchange.xforce.ibmcloud.com/vulnerabilities/8455
2002-07-03
Published