MEDIUM · 5.0

CVE-2002-0560

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprin...

Vulnerability Description

PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OracleApplication Server1.0.2
OracleApplication Server Web Cache2.0.0.0
OracleOracle8I8.1.7
OracleOracle9I9.0

References

FAQ

What is CVE-2002-0560?

CVE-2002-0560 is a vulnerability with a CVSS score of 5.0 (MEDIUM). PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprin...

How severe is CVE-2002-0560?

CVE-2002-0560 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2002-0560?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Application Server, Oracle Application Server Web Cache, Oracle Oracle8I, Oracle Oracle9I.