6.4
CVE-2002-1632
- EPSS 5.45%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 16.06.2026 21:59:41
- Erkennungen
Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Application Server Version 1.0.2
Oracle ≫ Application Server Version 1.0.2.1s
Oracle ≫ Application Server Version 1.0.2.2
Oracle ≫ Application Server Version 9.0.2.0.0
Oracle ≫ Application Server Version 9.0.2.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.45% | 0.917 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.4 | 10 | 4.9 |
AV:N/AC:L/Au:N/C:P/I:P/A:N
|
http://www.nextgenss.com/papers/hpoas.pdf
http://www.kb.cert.org/vuls/id/717827
http://www.kb.cert.org/vuls/id/SVIM-576QLZ
http://www.oracle.com/technology/deploy/security/pdf/ias_modplsql_alert.pdf
http://www.securityfocus.com/bid/6556
https://exchange.xforce.ibmcloud.com/vulnerabilities/8665