CVE

Id
4955  
CVE No.
CVE-2002-0564  
Status
Candidate  
Description
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.  
Phase
Proposed (20020611)  
Votes
ACCEPT(4) Alderson, Baker, Cole, Wall | MODIFY(1) Frech | NOOP(2) Cox, Foat  
Comments
Frech> XF:oracle-appserver-alternate-dad-access(8456)