CVE-2001-1372

Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.

Scoring

CVSS base score
0.51
EPSS probability
10.29%
Published
2003-04-02
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs