← Vulnerability feed

Vulnerability record · CVE-2002-0103 · published 25 March 2002

CVE-2002-0103: Oracle application server web cache vulnerability

Oracle · Application Server Web Cache

An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.

4.6 CVSS 2.0 Medium EPSS 0.62% · top 52.7%
4.6CVSS 2.0 base score
0.62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

An installer program for Oracle9iAS Web Cache 2.0.0.x creates executable and configuration files with insecure permissions, which allows local users to gain privileges by (1) running webcached or (2) obtaining the administrator password from webcache.xml.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0103 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0385Oracle application server web cache vulnerabilityHeap-based buffer overflow in Oracle 9i Application Server Web Cache 9.0.4.0.0, 9.0.3.1.0, 9.0.2.3.0, and 9.0.0.4.0 allows remote attackers to execut…EPSS 16%10.0CVE-2002-1641Oracle application server web cache vulnerabilityMultiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown ve…EPSS 9.1%7.5CVE-2002-0559Oracle application server vulnerabilityBuffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute ar…EPSS 13%7.5CVE-2002-0561Oracle application server vulnerabilityThe default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which …EPSS 9.7%7.5CVE-2002-0564Oracle application server vulnerabilityPL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DA…EPSS 5.1%7.5CVE-2001-0836Oracle application server web cache vulnerabilityBuffer overflow in Oracle9iAS Web Cache 2.0.0.1 allows remote attackers to execute arbitrary code via a long HTTP GET request.EPSS 15%6.8CVE-2005-1381Oracle application server web cache vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web script or HTML via the (1) c…EPSS 20%5.0CVE-2005-1382Oracle application server web cache vulnerabilityThe webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file paramete…EPSS 7.0%

Source: NIST National Vulnerability Database (record CVE-2002-0103), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.