Oracle Application Server vulnerabilities
193 known vulnerabilities affecting oracle/application_server.
Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15
Vulnerabilities
Page 1 of 10
CVE-2002-0656P3HIGHCVSS 7.5PoCv1.0.2v1.0.2.1s+1 more2002-08-12
CVE-2002-0656 [HIGH] CVE-2002-0656: Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a large session ID in SSL3.
nvd
CVE-2005-1383P3HIGHCVSS 7.5PoCv10.1.0.2v10.1.0.3+2 more2005-05-03
CVE-2005-1383 [HIGH] CVE-2005-1383: The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server a
The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a request to the webcache TCP port 7778.
nvd
CVE-2006-0287P3CRITICALCVSS 10.0PoCv10.1.2.0.22006-01-18
CVE-2006-0287 [CRITICAL] CVE-2006-0287: Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.
nvd
CVE-2004-1364P3HIGHCVSS 8.5PoCv9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1364 [HIGH] CWE-22 CVE-2004-1364: Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
nvd
CVE-2002-0840P4MEDIUMCVSS 6.8PoCv1.0.2v1.0.2.1s+3 more2002-10-11
CVE-2002-0840 [MEDIUM] CVE-2002-0840: Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and
Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS is present, allows remote attackers to execute script as other web page visitors via the Host: header, a different vulnerability than CAN-2002-1157.
nvd
CVE-2001-0419P3HIGHCVSS 7.5PoCv4.0.8.22001-07-02
CVE-2001-0419 [HIGH] CVE-2001-0419: Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web lis
Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.
nvd
CVE-2006-0586P3HIGHCVSS 7.5PoCv10.1.0.2v10.1.0.3+6 more2006-02-08
CVE-2006-0586 [HIGH] CWE-89 CVE-2006-0586: Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote atta
Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DEL
nvd
CVE-2020-1967P3HIGHCVSS 7.5v12.1.32020-04-21
CVE-2020-1967 [HIGH] CWE-476 CVE-2020-1967: Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 han
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by
nvd
CVE-2000-0169P3HIGHCVSS 7.5PoCv4.02000-03-15
CVE-2000-0169 [HIGH] CVE-2000-0169: Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
nvd
CVE-2009-0993P3HIGHCVSS 7.5v10.1.2.3.02009-04-15
CVE-2009-0993 [HIGH] CVE-2009-0993: Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote
Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that
nvd
CVE-2004-1707P4HIGHCVSS 7.2PoCv1.0.2v1.0.2.1s+10 more2004-07-30
CVE-2004-1707 [HIGH] CVE-2004-1707: The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix syste
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
nvd
CVE-2002-0659P4MEDIUMCVSS 5.0PoCv1.0.2v1.0.2.1s+1 more2002-08-12
CVE-2002-0659 [MEDIUM] CVE-2002-0659: The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
nvd
CVE-2004-1774P4HIGHCVSS 7.2PoCv10.1.0.22004-08-31
CVE-2004-1774 [HIGH] CVE-2004-1774: Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracl
Buffer overflow in the SDO_CODE_SIZE procedure of the MD2 package (MDSYS.MD2.SDO_CODE_SIZE) in Oracle 10g before 10.1.0.2 Patch 2 allows local users to execute arbitrary code via a long LAYER parameter.
nvd
CVE-2005-3204P4MEDIUMCVSS 4.3PoCv9.0.2v9.0.2.0.0+7 more2005-10-14
CVE-2005-3204 [MEDIUM] CVE-2005-3204: Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arb
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or HTML via the query string in an HTTP request.
nvd
CVE-2018-5407P4MEDIUMCVSS 4.7PoCv0.9.8v1.0.0+1 more2018-11-15
CVE-2018-5407 [MEDIUM] CWE-200 CVE-2018-5407: Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerab
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
nvd
CVE-2002-0386P4MEDIUMCVSS 5.0PoCv9.0.22002-11-04
CVE-2002-0386 [MEDIUM] CVE-2002-0386: The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows rem
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cause a denial of service (crash) via (1) an HTTP GET request containing a ".." (dot dot) sequence, or (2) a malformed HTTP GET request with a chunked Transfer-Encoding with missing data.
nvd
CVE-2008-7233P3CRITICALCVSS 9.3v1.1.8.262009-09-14
CVE-2008-7233 [CRITICAL] CVE-2008-7233: Unspecified vulnerability in the E-Business Application client, as used in Oracle Application Server
Unspecified vulnerability in the E-Business Application client, as used in Oracle Application Server 1.1.8.26 and E-Business Suite 11.5.10.2, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Oracle Jinitiator component, aka AS02.
nvd
CVE-2002-0569P3HIGHCVSS 7.5v1.0.22002-07-03
CVE-2002-0569 [HIGH] CVE-2002-0569: Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration
Oracle 9i Application Server allows remote attackers to bypass access restrictions for configuration files via a direct request to the XSQL Servlet (XSQLServlet).
nvd
CVE-2002-0563P3MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0563 [MEDIUM] CWE-287 CVE-2002-0563: The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to a
The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Services (1) dms0, (2) dms/DMSDump, (3) servlet/DMSDump, (4) servlet/Spy, (5) soap/servlet/Spy, and (6) dms/AggreSpy; and Oracle Java Process Manager (7) oprocmgr-status and (
nvd
CVE-2004-1371P3CRITICALCVSS 9.0v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1371 [CRITICAL] CWE-119 CVE-2004-1371: Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code v
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
nvd
1 / 10Next →