CVE Vulnerabilities

CVE-2002-1632

Published: Dec 31, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.4 MEDIUM
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.

Affected Software

NameVendorStart VersionEnd Version
Application_serverOracle1.0.2 (including)1.0.2 (including)
Application_serverOracle1.0.2.1s (including)1.0.2.1s (including)
Application_serverOracle1.0.2.2 (including)1.0.2.2 (including)
Application_serverOracle9.0.2.0.0 (including)9.0.2.0.0 (including)
Application_serverOracle9.0.2.0.1 (including)9.0.2.0.1 (including)

References