CVE-2002-0563
Last modified
CVE-2002-0563 is a vulnerability of currently unknown severity. The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.. EPSS estimates a 51.13% chance of exploitation in the next 30 days.
Description
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server | 1.0.2 |
| Oracle | Application Server Web Cache | 2.0.0.0 |
| Oracle | Application Server Web Cache | 2.0.0.1 |
| Oracle | Application Server Web Cache | 2.0.0.2 |
| Oracle | Application Server Web Cache | 2.0.0.3 |
| Oracle | Oracle8i | 8.1.7 |
| Oracle | Oracle8i | 8.1.7_.1 |
| Oracle | Oracle9i | 9.0 |
| Oracle | Oracle9i | 9.0.1 |
References
- http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdfPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2002-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/168795US Government Resource
- http://www.securityfocus.com/bid/4293Patch, Vendor Advisory
- http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdfPatch, Vendor Advisory
- http://www.cert.org/advisories/CA-2002-08.htmlPatch, Third Party Advisory, US Government Resource
- http://www.kb.cert.org/vuls/id/168795US Government Resource
- http://www.securityfocus.com/bid/4293Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0563?
How severe is CVE-2002-0563?
How do I fix CVE-2002-0563?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0557Vulnerability in OpenBSD 3.0, when using YP with netgroups i…
- CVE-2002-0558Directory traversal vulnerability in TYPSoft FTP server 0.97…
- CVE-2002-0559Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i App…
- CVE-2002-0560PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.…
- CVE-2002-0561The default configuration of the PL/SQL Gateway web administ…
- CVE-2002-0562The default configuration of Oracle 9i Application Server 1.…
- CVE-2002-0564PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.…
- CVE-2002-0565Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directo…
- CVE-2002-0566PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.…
- CVE-2002-0567Oracle 8i and 9i with PL/SQL package for External Procedures…
- CVE-2002-0568Oracle 9i Application Server stores XSQL and SOAP configurat…
- CVE-2002-0569Oracle 9i Application Server allows remote attackers to bypa…
Are you affected by CVE-2002-0563?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
