CVE-2002-1858
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the…
Does this matter?
Lower severity and a low EPSS score (4.53%). Track it; it rarely justifies an emergency change on its own.
Description
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 4.53% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/279582
- http://otn.oracle.com/deploy/security/pdf/2002alert47rev1.pdfPatch
- http://www.iss.net/security_center/static/9446.phpPatch
- http://www.securityfocus.com/bid/5119Patch
- http://www.westpoint.ltd.uk/advisories/wp-02-0002.txtPatch, Vendor Advisory
- http://online.securityfocus.com/archive/1/279582
- http://otn.oracle.com/deploy/security/pdf/2002alert47rev1.pdfPatch
- http://www.iss.net/security_center/static/9446.phpPatch
- http://www.securityfocus.com/bid/5119Patch
- http://www.westpoint.ltd.uk/advisories/wp-02-0002.txtPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.