CVE Vulnerabilities

CVE-2002-0561

Published: Jul 03, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.

Affected Software

NameVendorStart VersionEnd Version
Application_serverOracle1.0.2 (including)1.0.2 (including)
Application_server_web_cacheOracle2.0.0.0 (including)2.0.0.0 (including)
Application_server_web_cacheOracle2.0.0.1 (including)2.0.0.1 (including)
Application_server_web_cacheOracle2.0.0.2 (including)2.0.0.2 (including)
Application_server_web_cacheOracle2.0.0.3 (including)2.0.0.3 (including)
Oracle8iOracle8.1.7 (including)8.1.7 (including)
Oracle8iOracle8.1.7_.1 (including)8.1.7_.1 (including)
Oracle9iOracle9.0 (including)9.0 (including)
Oracle9iOracle9.0.1 (including)9.0.1 (including)

References