cbcvebase.
CVE-2004-1877
published 2004-03-30

CVE-2004-1877: The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO…

PriorityP415low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
3.00%
86.0th percentile
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.

Affected

15 ranges
VendorProductVersion rangeFixed in
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oracleapplication_server
oraclehttp_server
oraclehttp_server
oraclehttp_server
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.