← Vulnerability feed

Vulnerability record · CVE-2002-1062 · published 4 October 2002

CVE-2002-1062: T. hauck jana web server vulnerability

TT. Hauck · Jana Web Server

Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.

7.5 CVSS 2.0 High EPSS 2.7% · top 14.5%
7.5CVSS 2.0 base score
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Signedness error in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to execute arbitrary code via long (1) Username, (2) Password, or (3) Hostname entries.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-1062 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2002-1061T. hauck jana web server vulnerabilityMultiple buffer overflows in Thomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allow remote attackers to cause a denial of service a…EPSS 5.7%7.5CVE-2002-1065T. hauck jana web server vulnerabilityThomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, does not restrict the number of unsuccessful login attempts, which makes it easier…EPSS 1.4%7.5CVE-2002-1066T. hauck jana web server vulnerabilityThomas Hauck Jana Server 1.4.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large messa…EPSS 4.1%5.0CVE-2002-1063T. hauck jana web server vulnerabilityThomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, allows remote attackers to cause a denial of service (resource exhaustion) via a l…EPSS 2.4%5.0CVE-2002-1064T. hauck jana web server vulnerabilityThomas Hauck Jana Server 2.x through 2.2.1, and 1.4.6 and earlier, generates different responses for valid and invalid usernames, which allows remote…EPSS 2.3%5.0CVE-2001-0557T. hauck jana web server vulnerabilityT. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e).EPSS 11%5.0CVE-2001-0558T. hauck jana web server vulnerabilityT. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS devi…EPSS 7.3%5.0CVE-1999-1082T. hauck jana web server vulnerabilityDirectory traversal vulnerability in Jana proxy web server 1.40 allows remote attackers to ready arbitrary files via a "......" (modified dot dot) at…EPSS 6.6%

Source: NIST National Vulnerability Database (record CVE-2002-1062), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.