Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
2002-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 6.4 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | oracle | application_server | 1.0.2 | Yes |
Application | oracle | application_server | 1.0.2.1s | Yes |
Application | oracle | application_server | 1.0.2.2 | Yes |
Application | oracle | application_server | 9.0.2.0.0 | Yes |
Application | oracle | application_server | 9.0.2.0.1 | Yes |