CVE-2002-0103
Estado: ModificadaMedia (4.6)—
An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.61%
- Percentil entre todas las CVEs puntuadas: 48
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=101041510727937&w=2
- http://otn.oracle.com/deploy/security/pdf/webcache2.pdf
- http://www.iss.net/security_center/static/7766.php
- http://www.iss.net/security_center/static/7768.php
- http://www.securityfocus.com/bid/3761
- http://www.securityfocus.com/bid/3764
- http://marc.info/?l=bugtraq&m=101041510727937&w=2
- http://otn.oracle.com/deploy/security/pdf/webcache2.pdf
- http://www.iss.net/security_center/static/7766.php
- http://www.iss.net/security_center/static/7768.php
- http://www.securityfocus.com/bid/3761
- http://www.securityfocus.com/bid/3764
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0103",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-03-25T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=101041510727937&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://otn.oracle.com/deploy/security/pdf/webcache2.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/7766.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/7768.php",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/3761",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/3764",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=101041510727937&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://otn.oracle.com/deploy/security/pdf/webcache2.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/7766.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/7768.php",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/3761",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/3764",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml."
},
{
"lang": "es",
"value": "El programa de instalación para el Oracle9i Web cache 2.0.0.x crea ejecutables y archivos de configuración con permisos inseguros, que permiten a usuarios locales asignarse privilegios: (1) ejecutar webcache y (2) obtener la contraseña de administrador de webcache.xml."
}
],
"lastModified": "2026-06-16T21:56:48.200",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:application_server_web_cache:2.0.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2C272DE0-3717-40D0-99A6-2B4108BF85A3"
},
{
"criteria": "cpe:2.3:a:oracle:application_server_web_cache:2.0.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4959B7CD-218F-47A3-A604-629B69E1905B"
},
{
"criteria": "cpe:2.3:a:oracle:application_server_web_cache:2.0.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6659ECF3-D355-4357-BB15-DAFA427FCD12"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}