CVE-2002-0857
Estado: ModificadaAlta (7.5)—
Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 14%
- Percentil entre todas las CVEs puntuadas: 96
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=102933735716634&w=2
- http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf
- http://securitytracker.com/id?1005037
- http://www.kb.cert.org/vuls/id/301059
- http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt
- http://www.securityfocus.com/bid/5460
- http://marc.info/?l=bugtraq&m=102933735716634&w=2
- http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf
- http://securitytracker.com/id?1005037
- http://www.kb.cert.org/vuls/id/301059
- http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt
- http://www.securityfocus.com/bid/5460
JSON original (NVD)
Mostrar
{
"id": "CVE-2002-0857",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-09-05T04:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=102933735716634&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securitytracker.com/id?1005037",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/301059",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/5460",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=102933735716634&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://otn.oracle.com/deploy/security/pdf/2002alert40rev1.pdf",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securitytracker.com/id?1005037",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/301059",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ngssoftware.com/advisories/ora-lsnrfmtstr.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/5460",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Format string vulnerabilities in Oracle Listener Control utility (lsnrctl) for Oracle 9.2 and 9.0, 8.1, and 7.3.4, allow remote attackers to execute arbitrary code on the Oracle DBA system by placing format strings into certain entries in the listener.ora configuration file."
},
{
"lang": "es",
"value": "Vulnerabilidad de formato de cadenas en la utilidad Oracle Listener Control (lsnrctl) en Oracle 9.2, 9.0, 8.1 y 7.3.4 permite a atacantes remotos ejecutar código arbitrario el sitstema Oracle DBA mediante la introducción de cadenas de formato en ciertas entradas en fichero de configuración listener.ora"
}
],
"lastModified": "2026-06-16T21:58:16.570",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:database_server:7.3.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE07BAF7-3A9A-426B-9536-72EAB8984A4F"
},
{
"criteria": "cpe:2.3:a:oracle:database_server:9.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7AC3C795-3914-4941-9244-D4FB9C12C7F9"
},
{
"criteria": "cpe:2.3:a:oracle:database_server:9.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3D159781-4109-4A9B-A46B-241021FED68E"
},
{
"criteria": "cpe:2.3:a:oracle:oracle8i:8.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44943278-DF79-4C58-AA98-B3FEA6CB8F21"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}