CVE-2002-0563

Oracle Application Server - Authentication Bypass

Title source: rule

Description

The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.

Scores

EPSS 0.3445
EPSS Percentile 96.9%

Classification

CWE
CWE-287
Status draft

Affected Products (9)

oracle/application_server
oracle/application_server_web_cache
oracle/application_server_web_cache
oracle/application_server_web_cache
oracle/application_server_web_cache
oracle/oracle8i
oracle/oracle8i
oracle/oracle9i
oracle/oracle9i

Timeline

Published Jul 03, 2002
Tracked Since Feb 18, 2026