Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
References
Link | Resource |
---|---|
http://www.nextgenss.com/papers/hpoas.pdf | Patch |
http://www.kb.cert.org/vuls/id/SVIM-576QLZ | Patch US Government Resource |
http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf | |
http://www.kb.cert.org/vuls/id/717827 | US Government Resource |
http://www.securityfocus.com/bid/6556 | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8665 |
Configurations
Configuration 1 (hide)
|
Information
Published : 2002-12-30 21:00
Updated : 2017-07-10 18:29
NVD link : CVE-2002-1632
Mitre link : CVE-2002-1632
JSON object : View
CWE
Products Affected
oracle
- application_server