CVE-2002-0563

Severity
5.0MEDIUM
EPSS
34.5%
top 3.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateApr 30

Description

The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDoracle/application4 versions+3
NVDoracle/oracle8i8.1.7, 8.1.7_.1+1
NVDoracle/oracle9i9.0, 9.0.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c5h7-mjwp-4pvr: The default configuration of Oracle 9i Application Server 12022-04-30
CVEList
CVE-2002-0563: The default configuration of Oracle 9i Application Server 12002-06-11