CVE-2002-0566

3 documents3 sources
Severity
5.0MEDIUM
EPSS
2.6%
top 14.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateApr 30

Description

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDoracle/application4 versions+3
NVDoracle/oracle8i8.1.7, 8.1.7_.1+1
NVDoracle/oracle9i9.0, 9.0.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rqj8-mrx8-w87x: PL/SQL module 32022-04-30
CVEList
CVE-2002-0566: PL/SQL module 32002-06-11
CVE-2002-0566 (MEDIUM CVSS 5) | PL/SQL module 3.0.9.8.2 in Oracle 9 | cvebase.io