← Vulnerability feed

Vulnerability record · CVE-2001-1217 · published 21 December 2001

CVE-2001-1217: Oracle 9i Application Server PL/SQL module directory traversal

Oracle · Application Server

The PL/SQL Apache module in Oracle 9i Application Server is vulnerable to directory traversal, allowing a remote attacker to read files outside the intended web root. The flaw is triggered by a double-encoded URL containing dot-dot sequences, which bypasses path filtering. It matters because sensitive files on the server can be exposed without authentication.

5.0 CVSS 2.0 Medium EPSS 54% · top 1.0%
5.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote, unauthenticated information disclosure with a high EPSS percentile, though impact is limited to confidentiality and no KEV listing or confirmed exploit is present.

What it is

The PL/SQL Apache module in Oracle 9i Application Server is vulnerable to directory traversal, allowing a remote attacker to read files outside the intended web root. The flaw is triggered by a double-encoded URL containing dot-dot sequences, which bypasses path filtering. It matters because sensitive files on the server can be exposed without authentication.

Impact

An attacker gains read access to sensitive information on the server, such as configuration or application files reachable by the web process. No write or code execution is described in the record.

Attack surface

Reachable remotely over the network through the PL/SQL Apache module via a crafted double-encoded URL. The CVSS vector indicates no authentication (Au:N) and no user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.54383, 98.96th percentile), and references are vendor and third-party advisories with patch tags, but no public exploit code is confirmed in the record.

What to do

  • Apply the Oracle patch referenced in the vendor advisory (modplsql.pdf) and CERT/CC advisory VU#758483.
  • Disable or restrict the PL/SQL Apache module if it is not required.
  • Normalize and reject double-encoded and dot-dot sequences at the web server or reverse proxy layer.
  • Run the web service with least privilege and restrict filesystem access to only required directories.
  • Monitor vendor advisories for updated guidance since the record is old and product version detail is absent.

Detection

  • Inspect web server and PL/SQL module logs for URLs containing double-encoded dot-dot sequences (e.g., %252e%252e) or repeated traversal patterns.
  • Alert on requests to the PL/SQL module that return files outside expected web content paths.
  • Baseline normal PL/SQL module request patterns and flag anomalous path traversal attempts.
  • Review file access logs for reads of sensitive files by the web service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-1217 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1812Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Enterprise Manager component in Oracle Database 9.0.1.5 FIPS+; Application Server 1.0.2.2; and Enterprise Man…EPSS 2.1%10.0CVE-2008-1824Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Dynamic Monitoring Service component in Oracle Application Server 9.0.4.3, 10.1.2.2, and 10.1.3.3 has unknown…EPSS 3.4%10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%10.0CVE-2008-0345Oracle application server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 2.6%10.0CVE-2008-0346Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact …EPSS 2.7%10.0CVE-2008-0347Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Ap…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2001-1217), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.