← Vulnerability feed

Vulnerability record · CVE-2002-0568 · published 3 July 2002

CVE-2002-0568: Oracle 9i Application Server exposes XSQL and SOAP config files with credentials

Oracle · Application Server

Oracle 9i Application Server stores XSQLConfig.xml and soapConfig.xml in a location reachable through a virtual directory, so the files can be retrieved without proper access control. These configuration files contain sensitive information including usernames and passwords. Exposure of stored credentials can lead to further compromise of the application server and connected systems.

2.1 CVSS 2.0 Low EPSS 75% · top 0.5%
2.1CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.

AV:L/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw exposes plaintext credentials, but the CVSS 2.0 score is only 2.1 and the record lacks confirmed in-the-wild exploitation, so it ranks below critical.

What it is

Oracle 9i Application Server stores XSQLConfig.xml and soapConfig.xml in a location reachable through a virtual directory, so the files can be retrieved without proper access control. These configuration files contain sensitive information including usernames and passwords. Exposure of stored credentials can lead to further compromise of the application server and connected systems.

Impact

An attacker who retrieves the files gains usernames and passwords used by the application server, enabling credential reuse against the server or backend data sources. The direct impact is information disclosure, not code execution.

Attack surface

The files are requested over HTTP through a virtual directory, so the flaw is network-reachable despite the local access vector in the CVSS score. No authentication or user interaction is described as required to request the files.

Exploitation

The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.75176 (99.5th percentile), indicating elevated predicted exploitation activity. References include vendor and CERT advisories with patch tags, but no public exploit code is confirmed in the supplied data.

What to do

  • Apply the Oracle and CERT/CC patch guidance referenced in CA-2002-08 and VU#476619, or upgrade to a fixed Oracle Application Server release.
  • Remove or block virtual directory access to XSQLConfig.xml and soapConfig.xml at the web server or application server layer.
  • Rotate any credentials stored in those configuration files, since they may already have been exposed.
  • Restrict network access to the application server's administrative and configuration paths to trusted hosts only.

Detection

  • Monitor web and application server logs for HTTP requests to XSQLConfig.xml or soapConfig.xml, especially from unexpected source addresses.
  • Alert on access to configuration file paths outside normal administrative workflows.
  • Review authentication logs for use of the credentials stored in those files from unusual locations or at unusual times.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0568 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1812Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Enterprise Manager component in Oracle Database 9.0.1.5 FIPS+; Application Server 1.0.2.2; and Enterprise Man…EPSS 2.1%10.0CVE-2008-1824Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Dynamic Monitoring Service component in Oracle Application Server 9.0.4.3, 10.1.2.2, and 10.1.3.3 has unknown…EPSS 3.4%10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%10.0CVE-2008-0345Oracle application server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 2.6%10.0CVE-2008-0346Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact …EPSS 2.7%10.0CVE-2008-0347Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Ap…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2002-0568), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.