CVE-2002-0568
published 2002-07-03CVE-2002-0568: Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames…
PriorityP424low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
75.18%
99.5th percentile
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | oracle8i | — | — |
| oracle | oracle8i | — | — |
| oracle | oracle9i | — | — |
| oracle | oracle9i | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://marc.info/?l=bugtraq&m=101301813117562&w=2http://www.cert.org/advisories/CA-2002-08.htmlhttp://www.kb.cert.org/vuls/id/476619http://www.nextgenss.com/papers/hpoas.pdfhttp://www.securityfocus.com/bid/4290http://marc.info/?l=bugtraq&m=101301813117562&w=2http://www.cert.org/advisories/CA-2002-08.htmlhttp://www.kb.cert.org/vuls/id/476619http://www.nextgenss.com/papers/hpoas.pdfhttp://www.securityfocus.com/bid/4290
2002-07-03
Published