Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2002-2323
http://www.securityfocus.com/bid/7395
http://www.iss.net/security_center/static/9841.php
http://otn.oracle.com/deploy/security/pdf/2002alert39rev1.pdf