CVE-2002-0563: Oracle Application Server
Medium severity, CVSS 5.0. EPSS: 51.1% chance of exploitation in the next 30 days.
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (8) oprocmgr-service, which can be used to control Java processes.
Affected products
- Oracle Application Server: version 1.0.2 only
- Oracle Application Server Web Cache: version 2.0.0.0 only; version 2.0.0.1 only; version 2.0.0.2 only; version 2.0.0.3 only
- Oracle ORACLE8I: version 8.1.7 only; version 8.1.7_.1 only
- Oracle ORACLE9I: version 9.0 only; version 9.0.1 only
Published 2002-07-03. Last modified 2026-06-16.