Oracle Oracle9I vulnerabilities

47 known vulnerabilities affecting oracle/oracle9i.

Total CVEs
47
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH18MEDIUM19LOW2

Vulnerabilities

Page 3 of 3
CVE-2002-0561HIGHCVSS 7.5v9.0v9.0.12002-07-03
CVE-2002-0561 [HIGH] CVE-2002-0561: The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Applicatio The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.
nvd
CVE-2002-0566MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0566 [MEDIUM] CVE-2002-0566: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a d PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.
nvd
CVE-2002-0565MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0565 [MEDIUM] CVE-2002-0565: Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
nvd
CVE-2002-0563MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0563 [MEDIUM] CWE-287 CVE-2002-0563: The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to a The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (
nvd
CVE-2002-0560MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0560 [MEDIUM] CVE-2002-0560: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain se PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.
nvd
CVE-2002-0562MEDIUMCVSS 5.0v9.0v9.0.12002-07-03
CVE-2002-0562 [MEDIUM] CVE-2002-0562: The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP store The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.
nvd
CVE-2002-0568LOWCVSS 2.1v9.0v9.0.12002-07-03
CVE-2002-0568 [LOW] CVE-2002-0568: Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
nvd