Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-2138

CWE-2645 documents4 sources
Severity
5.0MEDIUM
EPSS
42.4%
top 2.54%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMay 12
Latest updateMay 1

Description

Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-q5xw-x27x-5723: Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/po2022-05-01
CVEList
CVE-2008-2138: Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/po2008-05-12

💥Exploits & PoCs

2
Exploit-DB
Oracle Application Server Portal 10g - Authentication Bypass2008-05-09
Exploit-DB
LulieBlog 1.0.1 - Remote Authentication Bypass2008-01-15