Back

CVE-2002-1631

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.

Published: Dec 31, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (5)

Vendor Product Version
oracle application_server 1.0.2
oracle application_server 1.0.2.1s
oracle application_server 1.0.2.2
oracle application_server 9.0.2.0.0
oracle application_server 9.0.2.0.1

GitHub Security Advisory GHSA-m54v-h5r2-5m3r

SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS)...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 7.67%

Top 6% most likely to be exploited

Threat Score 32.3 / 100

Data Sources

NVD EPSS GitHub