Back

CVE-2001-0591

Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.

Published: Aug 22, 2001 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
oracle application_server 1.0.2
oracle jsp *

GitHub Security Advisory GHSA-ppgw-xx7q-mwfh

Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 4.01%

Top 10% most likely to be exploited

Threat Score 31.2 / 100

Data Sources

NVD EPSS GitHub