Oracle Application Express vulnerabilities
47 known vulnerabilities affecting oracle/application_express.
Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2MEDIUM41
Vulnerabilities
Page 2 of 3
CVE-2020-27193MEDIUMCVSS 6.1fixed in 21.1.0.00.012020-11-12
CVE-2020-27193 [MEDIUM] CWE-79 CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows rem
A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
nvd
CVE-2020-7760HIGHCVSS 7.5fixed in 20.22020-10-30
CVE-2020-7760 [MEDIUM] CWE-400 CVE-2020-7760: This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirro
This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-patt
nvd
CVE-2020-14763MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14763 [MEDIUM] CVE-2020-14763: Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The
Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Quick Poll. Successful attacks requir
nvd
CVE-2020-14898MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14898 [MEDIUM] CVE-2020-14898: Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. T
Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Packaged Apps. Successful attacks
nvd
CVE-2020-14899MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14899 [MEDIUM] CVE-2020-14899: Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. T
Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful attacks
nvd
CVE-2020-14900MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14900 [MEDIUM] CVE-2020-14900: Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server.
Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Group Calendar. Successful attack
nvd
CVE-2020-14762MEDIUMCVSS 5.4fixed in 20.22020-10-21
CVE-2020-14762 [MEDIUM] CVE-2020-14762: Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported v
Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a
nvd
CVE-2020-26870MEDIUMCVSS 6.1fixed in 21.1.0.00.012020-10-07
CVE-2020-26870 [MEDIUM] CWE-79 CVE-2020-26870: Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip
Cure53 DOMPurify before 2.0.17 allows mutation XSS. This occurs because a serialize-parse roundtrip does not necessarily return the original DOM tree, and a namespace can change from HTML to MathML, as demonstrated by nesting of FORM elements.
nvd
CVE-2020-2972MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2972 [MEDIUM] CWE-79 CVE-2020-2972: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a p
nvd
CVE-2020-2975MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2975 [MEDIUM] CVE-2020-2975: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2977MEDIUMCVSS 4.6≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2977 [MEDIUM] CVE-2020-2977: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a pe
nvd
CVE-2020-2971MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2971 [MEDIUM] CVE-2020-2971: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2974MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2974 [MEDIUM] CVE-2020-2974: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2513MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2513 [MEDIUM] CWE-79 CVE-2020-2513: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a p
nvd
CVE-2020-2973MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2973 [MEDIUM] CVE-2020-2973: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2976MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2976 [MEDIUM] CVE-2020-2976: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi
Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-11023MEDIUMCVSS 6.1KEVPoCfixed in 20.22020-04-29
CVE-2020-11023 [MEDIUM] CWE-79 CVE-2020-11023: In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option>
In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2020-2514MEDIUMCVSS 4.6fixed in 19.22020-04-15
CVE-2020-2514 [MEDIUM] CVE-2020-2514: Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported v
Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful attacks require human interaction from a
nvd
CVE-2020-9281MEDIUMCVSS 6.1fixed in 20.22020-03-07
CVE-2020-9281 [MEDIUM] CWE-79 CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 a
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
nvd
CVE-2019-10219MEDIUMCVSS 6.1v21.1.42019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd