CVE Vulnerabilities

CVE-2001-0326

Published: May 03, 2001 | Modified: Oct 10, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the «ALL FILES» FilePermission.

Affected Software

Name Vendor Start Version End Version
Application_server Oracle release_1.0.2.0.1 (including) release_1.0.2.0.1 (including)
Oracle8i Oracle 8.1.7_r3 (including) 8.1.7_r3 (including)

References