Unrated severityNVD Advisory· Published Oct 4, 2002· Updated Apr 16, 2026
CVE-2002-0947
CVE-2002-0947
Description
Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter.
Affected products
2- cpe:2.3:a:oracle:application_server:9.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:reports:6.0.8:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.iss.net/security_center/static/9289.phpnvdPatchVendor Advisory
- www.kb.cert.org/vuls/id/997403nvdPatchThird Party AdvisoryUS Government Resource
- www.securityfocus.com/bid/4848nvdPatchVendor Advisory
- archives.neohapsis.com/archives/vulnwatch/2002-q2/0097.htmlnvd
- online.securityfocus.com/archive/1/276524nvd
- technet.oracle.com/deploy/security/pdf/reports6i_alert.pdfnvd
- www.nextgenss.com/vna/ora-reports.txtnvd
News mentions
0No linked articles in our index yet.