Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Application_server | Oracle | 1.0.2 (including) | 1.0.2 (including) |
Application_server | Oracle | 1.0.2.1s (including) | 1.0.2.1s (including) |
Application_server | Oracle | 1.0.2.2 (including) | 1.0.2.2 (including) |
Application_server | Oracle | 9.0.2.0.0 (including) | 9.0.2.0.0 (including) |
Application_server | Oracle | 9.0.2.0.1 (including) | 9.0.2.0.1 (including) |