CVE-2002-1637
Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many…
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many others, which allows attackers to gain privileges.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.57% probability · 46th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/712723Third Party Advisory, US Government Resource
- http://www.nextgenss.com/papers/hpoas.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/968
- https://exchange.xforce.ibmcloud.com/vulnerabilities/969
- https://exchange.xforce.ibmcloud.com/vulnerabilities/970
- https://exchange.xforce.ibmcloud.com/vulnerabilities/971
- https://exchange.xforce.ibmcloud.com/vulnerabilities/972
- http://www.kb.cert.org/vuls/id/712723Third Party Advisory, US Government Resource
- http://www.nextgenss.com/papers/hpoas.pdf
- https://exchange.xforce.ibmcloud.com/vulnerabilities/968
- https://exchange.xforce.ibmcloud.com/vulnerabilities/969
- https://exchange.xforce.ibmcloud.com/vulnerabilities/970
- https://exchange.xforce.ibmcloud.com/vulnerabilities/971
- https://exchange.xforce.ibmcloud.com/vulnerabilities/972
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.