Unrated severityNVD Advisory· Published Oct 4, 2002· Updated Apr 16, 2026
CVE-2002-1089
CVE-2002-1089
Description
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
Affected products
3- cpe:2.3:a:oracle:application_server:9.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:reports:6.0.8:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:reports:6.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:reports:6.0.8.19:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.