CVE-2002-0568
low · 2.1Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
2.1
CVSS
75.2%
EPSS (exploit prob.)
99th
EPSS percentile
2002-07-03
Published
AV:L/AC:L/Au:N/C:P/I:N/A:N
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| oracle | application_server | 1.0.2 |
| oracle | oracle8i | 8.1.7 |
| oracle | oracle8i | 8.1.7.1 |
| oracle | oracle9i | 9.0 |
| oracle | oracle9i | 9.0.1 |
Check a specific version with /api/v1/cve/match.
References
- http://marc.info/?l=bugtraq&m=101301813117562&w=2
- http://www.cert.org/advisories/CA-2002-08.html
- http://www.kb.cert.org/vuls/id/476619
- http://www.nextgenss.com/papers/hpoas.pdf
- http://www.securityfocus.com/bid/4290
- http://marc.info/?l=bugtraq&m=101301813117562&w=2
- http://www.cert.org/advisories/CA-2002-08.html
- http://www.kb.cert.org/vuls/id/476619
- http://www.nextgenss.com/papers/hpoas.pdf
- http://www.securityfocus.com/bid/4290
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2002-0568