Vulnerability record · CVE-2002-0568 · published 3 July 2002
CVE-2002-0568: Oracle 9i Application Server exposes XSQL and SOAP config files with credentials
Oracle · Application Server
Oracle 9i Application Server stores XSQLConfig.xml and soapConfig.xml in a location reachable through a virtual directory, so the files can be retrieved without proper access control. These configuration files contain sensitive information including usernames and passwords. Exposure of stored credentials can lead to further compromise of the application server and connected systems.
Description
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
AV:L/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityThe flaw exposes plaintext credentials, but the CVSS 2.0 score is only 2.1 and the record lacks confirmed in-the-wild exploitation, so it ranks below critical.
What it is
Oracle 9i Application Server stores XSQLConfig.xml and soapConfig.xml in a location reachable through a virtual directory, so the files can be retrieved without proper access control. These configuration files contain sensitive information including usernames and passwords. Exposure of stored credentials can lead to further compromise of the application server and connected systems.
Impact
An attacker who retrieves the files gains usernames and passwords used by the application server, enabling credential reuse against the server or backend data sources. The direct impact is information disclosure, not code execution.
Attack surface
The files are requested over HTTP through a virtual directory, so the flaw is network-reachable despite the local access vector in the CVSS score. No authentication or user interaction is described as required to request the files.
Exploitation
The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.75176 (99.5th percentile), indicating elevated predicted exploitation activity. References include vendor and CERT advisories with patch tags, but no public exploit code is confirmed in the supplied data.
What to do
- Apply the Oracle and CERT/CC patch guidance referenced in CA-2002-08 and VU#476619, or upgrade to a fixed Oracle Application Server release.
- Remove or block virtual directory access to XSQLConfig.xml and soapConfig.xml at the web server or application server layer.
- Rotate any credentials stored in those configuration files, since they may already have been exposed.
- Restrict network access to the application server's administrative and configuration paths to trusted hosts only.
Detection
- Monitor web and application server logs for HTTP requests to XSQLConfig.xml or soapConfig.xml, especially from unexpected source addresses.
- Alert on access to configuration file paths outside normal administrative workflows.
- Review authentication logs for use of the credentials stored in those files from unusual locations or at unusual times.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=101301813117562&w=2 | |
| http://www.cert.org/advisories/CA-2002-08.html | PatchThird Party AdvisoryUS Government Resource |
| http://www.kb.cert.org/vuls/id/476619 | PatchThird Party AdvisoryUS Government Resource |
| http://www.nextgenss.com/papers/hpoas.pdf | |
| http://www.securityfocus.com/bid/4290 | Vendor Advisory |
| http://marc.info/?l=bugtraq&m=101301813117562&w=2 | |
| http://www.cert.org/advisories/CA-2002-08.html | PatchThird Party AdvisoryUS Government Resource |
| http://www.kb.cert.org/vuls/id/476619 | PatchThird Party AdvisoryUS Government Resource |
| http://www.nextgenss.com/papers/hpoas.pdf | |
| http://www.securityfocus.com/bid/4290 | Vendor Advisory |
Track CVE-2002-0568 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2002-0568), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.