CVE-2007-0280Improper Restriction of Operations within the Bounds of a Memory Buffer in Oracle Application Server

3 documents3 sources
Severity
7.5HIGHNVD
EPSS
2.2%
top 15.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateMay 1

Description

Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OPMN01 is for a buffer overflow in Oracle Notification Service (ONS).

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

NVDoracle/http_server9.0.1.5
NVDoracle/application_server10.1.2.0.2, 10.1.2.2, 9.0.4.3+2
NVDoracle/collaboration_suite10.1.2, 9.0.4.2+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-q89v-65jp-xc8g: Unspecified vulnerability in Oracle HTTP Server 92022-05-01
CVEList
CVE-2007-0280: Unspecified vulnerability in Oracle HTTP Server 92007-01-17
CVE-2007-0280 — Oracle Application Server vulnerability | cvebase