CVE-2002-0563
Oracle Application Server - Authentication Bypass
Title source: ruleDescription
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
Scores
EPSS
0.3445
EPSS Percentile
96.9%
Classification
CWE
CWE-287
Status
draft
Affected Products (9)
oracle/application_server
oracle/application_server_web_cache
oracle/application_server_web_cache
oracle/application_server_web_cache
oracle/application_server_web_cache
oracle/oracle8i
oracle/oracle8i
oracle/oracle9i
oracle/oracle9i
Timeline
Published
Jul 03, 2002
Tracked Since
Feb 18, 2026