← Vulnerability feed

Vulnerability record · CVE-2002-0842 · published 3 March 2003

CVE-2002-0842: Oracle application server vulnerability

Oracle · Application Server

Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which is then used in a call to ap_log_rerror().

7.5 CVSS 2.0 High EPSS 15% · top 3.5%
7.5CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which is then used in a call to ap_log_rerror().

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0076.html
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104559446010858&w=2
http://marc.info/?l=bugtraq&m=104560577227981&w=2
http://otn.oracle.com/deploy/security/pdf/2003alert52.pdf PatchVendor Advisory
http://www.cert.org/advisories/CA-2003-05.html US Government Resource
http://www.ciac.org/ciac/bulletins/n-046.shtml
http://www.iss.net/security_center/static/11330.php Vendor Advisory
http://www.kb.cert.org/vuls/id/849993 ExploitPatchThird Party AdvisoryUS Government Resource
http://www.nextgenss.com/advisories/ora-appservfmtst.txt
http://www.securityfocus.com/bid/6846
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0076.html
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104549708626309&w=2
http://marc.info/?l=bugtraq&m=104559446010858&w=2
http://marc.info/?l=bugtraq&m=104560577227981&w=2
http://otn.oracle.com/deploy/security/pdf/2003alert52.pdf PatchVendor Advisory
http://www.cert.org/advisories/CA-2003-05.html US Government Resource
http://www.ciac.org/ciac/bulletins/n-046.shtml
http://www.iss.net/security_center/static/11330.php Vendor Advisory
http://www.kb.cert.org/vuls/id/849993 ExploitPatchThird Party AdvisoryUS Government Resource
http://www.nextgenss.com/advisories/ora-appservfmtst.txt
http://www.securityfocus.com/bid/6846

Track CVE-2002-0842 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-1812Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Enterprise Manager component in Oracle Database 9.0.1.5 FIPS+; Application Server 1.0.2.2; and Enterprise Man…EPSS 2.1%10.0CVE-2008-1824Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Dynamic Monitoring Service component in Oracle Application Server 9.0.4.3, 10.1.2.2, and 10.1.3.3 has unknown…EPSS 3.4%10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%10.0CVE-2008-0345Oracle application server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 2.6%10.0CVE-2008-0346Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact …EPSS 2.7%10.0CVE-2008-0347Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Ap…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2002-0842), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.