CVE-2002-0568
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 75.2%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 75.18% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server · oracle/oracle8i · oracle/oracle9i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=101301813117562&w=2
- http://www.cert.org/advisories/CA-2002-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/476619Patch, Third Party Advisory, US Government Resource
- http://www.nextgenss.com/papers/hpoas.pdf
- http://www.securityfocus.com/bid/4290Vendor Advisory
- http://marc.info/?l=bugtraq&m=101301813117562&w=2
- http://www.cert.org/advisories/CA-2002-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/476619Patch, Third Party Advisory, US Government Resource
- http://www.nextgenss.com/papers/hpoas.pdf
- http://www.securityfocus.com/bid/4290Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.