# CVE-2002-1637

## Summary

- **CVE ID:** CVE-2002-1637
- **Severity:** UNKNOWN
- **CVSS Score:** 0.01
- **CWE:** N/A
- **Published:** Mar 28, 2005
- **Last Modified:** Mar 16, 2026

## Description

Multiple components in Oracle 9i Application Server (9iAS) are installed with over 160 default usernames and passwords, including (1) SYS, (2) SYSTEM, (3) AQJAVA, (4) OWA, (5) IMAGEUSER, (6) USER1, (7) USER2, (8) PLSQL, (9) DEMO, (10) FINANCE, and many others, which allows attackers to gain privileges.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/972)
- [CNA](http://www.kb.cert.org/vuls/id/712723)
- [CNA](http://www.nextgenss.com/papers/hpoas.pdf)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/968)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/971)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/969)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/970)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 35.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._