VulnerabilityModified
CVE-2002-0103
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
MEDIUM 4.6EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.61% probability · 48th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server web cache
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101041510727937&w=2
- http://otn.oracle.com/deploy/security/pdf/webcache2.pdfPatch, Vendor Advisory
- http://www.iss.net/security_center/static/7766.php
- http://www.iss.net/security_center/static/7768.php
- http://www.securityfocus.com/bid/3761
- http://www.securityfocus.com/bid/3764
- http://marc.info/?l=bugtraq&m=101041510727937&w=2
- http://otn.oracle.com/deploy/security/pdf/webcache2.pdfPatch, Vendor Advisory
- http://www.iss.net/security_center/static/7766.php
- http://www.iss.net/security_center/static/7768.php
- http://www.securityfocus.com/bid/3761
- http://www.securityfocus.com/bid/3764
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.