CVE-2002-1858
Last modified
CVE-2002-1858 is a vulnerability of currently unknown severity. Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").. EPSS estimates a 4.53% chance of exploitation in the next 30 days.
Description
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Application Server | 1.0.2.2 |
| Oracle | Application Server | 9.0.2 |
| Oracle | Application Server | 9.0.2.0.0 |
| Oracle | Application Server | 9.0.2.0.1 |
References
- http://www.westpoint.ltd.uk/advisories/wp-02-0002.txtPatch, Vendor Advisory
- http://www.westpoint.ltd.uk/advisories/wp-02-0002.txtPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-1858?
How severe is CVE-2002-1858?
How do I fix CVE-2002-1858?
Are you affected by CVE-2002-1858?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
