CVE-2007-0280
published 2007-01-17CVE-2007-0280: Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.07%
86.2th percentile
Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | application_server | — | — |
| oracle | collaboration_suite | — | — |
| oracle | collaboration_suite | — | — |
| oracle | enterprise_grid_console_server | — | — |
| oracle | http_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q89v-65jp-xc8g: Unspecified vulnerability in Oracle HTTP Server 9
ghsa_unreviewed·2022-05-01
CVE-2007-0280 [HIGH] GHSA-q89v-65jp-xc8g: Unspecified vulnerability in Oracle HTTP Server 9
Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).
GHSA
GHSA-cg98-rw53-3v8h: Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2007-5561 [HIGH] CWE-134 GHSA-cg98-rw53-3v8h: Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10
Format string vulnerability in the logging function in the Oracle OPMN daemon, as used on Oracle Enterprise Grid Console server 10.2.0.1, allows remote attackers to execute arbitrary code via format string specifiers in the URI in an HTTP request to port 6003, aka Oracle reference number 6296175. NOTE: this might be the same issue as CVE-2007-0282 or CVE-2007-0280, but there are insufficient details to be sure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://osvdb.org/32905http://secunia.com/advisories/23794http://securitytracker.com/id?1017522http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.htmlhttp://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.htmlhttp://www.securityfocus.com/bid/22083http://www.us-cert.gov/cas/techalerts/TA07-017A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/31541http://osvdb.org/32905http://secunia.com/advisories/23794http://securitytracker.com/id?1017522http://www.oracle.com/technetwork/topics/security/cpujan2007-101493.htmlhttp://www.red-database-security.com/advisory/oracle_buffer_overflow_ons.htmlhttp://www.securityfocus.com/bid/22083http://www.us-cert.gov/cas/techalerts/TA07-017A.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/31541
2007-01-17
Published