CVE-2001-0126Oracle Oracle8i vulnerability

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
0.8%
top 25.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 12
Latest updateApr 30

Description

Oracle XSQL servlet 1.0.3.0 and earlier allows remote attackers to execute arbitrary Java code by redirecting the XSQL server to another source via the xml-stylesheet parameter in the xslt stylesheet.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDoracle/oracle8i8.1.7

🔴Vulnerability Details

2
GHSA
GHSA-82qj-m6p5-xrm7: Oracle XSQL servlet 12022-04-30
CVEList
CVE-2001-0126: Oracle XSQL servlet 12001-05-07