CVE-2002-0563
15Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 51%
exploitation probability
51%top 1% of all CVEs
observed exploitation
nono source reports it
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
Affected products
n/a · n/aReferences
http://marc.info/?l=bugtraq&m=101301813117562&w=2http://otn.oracle.com/deploy/security/pdf/ias_modplsql_alert.pdfhttp://securitytracker.com/id?1009167https://exchange.xforce.ibmcloud.com/vulnerabilities/8455http://www.appsecinc.com/Policy/PolicyCheck7024.htmlhttp://www.cert.org/advisories/CA-2002-08.htmlhttp://www.kb.cert.org/vuls/id/168795http://www.nextgenss.com/papers/hpoas.pdfhttp://www.osvdb.org/13152http://www.osvdb.org/705http://www.securityfocus.com/bid/4293