SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2002-0563

The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy,…

MEDIUM 5.0EPSS 51.1%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 51.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
51.13% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
oracle/application server · oracle/application server web cache · oracle/oracle8i · oracle/oracle9i
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.