CVE-2001-1372

Loading...

General

Score:5.0/10.0
Severity:Medium
Category:N/A
Exploit:Available

Impact Metrics

Confidentiality:Partial
Integrity:None
Availability:None

Exploitability Metrics

Access Vector:Network
Access Complexity:Low
Authentication:None

Published on 06/02/02 - Updated on 10/10/17

Description

Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.

Category:

There is insufficient information about the issue to classify it; details are unknown or unspecified.

Security Notices

US National Vulnerability DatabaseCVE-2001-1372

Exploits

SecurityFocusBID-3341

Relative technologies

VendorProduct
oracleapplication_server

Share this vulnerability with:

Twitter Facebook LinkedIn Mail