peter bassill · operator
$ cve CVE-2002-1089 JSON

CVE-2002-1089 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 5.4% (pctl 92)

Patch early

A public exploit exists.

Description

rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS5.45% — more likely to be exploited than 92% of all CVEs
On CISA KEVno
Public exploityes
Published2002-10-04
Last modified2026-06-16

Affected (2)

VendorProduct
oracleapplication server
oraclereports

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD