Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many others, which allows attackers to gain privileges.
References
Configurations
History
20 Nov 2024, 23:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.kb.cert.org/vuls/id/712723 - Third Party Advisory, US Government Resource | |
References | () http://www.nextgenss.com/papers/hpoas.pdf - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/968 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/969 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/970 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/971 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/972 - |
Information
Published : 2002-02-26 05:00
Updated : 2024-11-20 23:41
NVD link : CVE-2002-1637
Mitre link : CVE-2002-1637
CVE.ORG link : CVE-2002-1637
JSON object : View
Products Affected
oracle
- application_server
CWE