Oracle Application Server vulnerabilities

193 known vulnerabilities affecting oracle/application_server.

Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15

Vulnerabilities

Page 10 of 10
CVE-2002-0560MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0560 [MEDIUM] CVE-2002-0560: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain se PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.
nvd
CVE-2002-0562MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0562 [MEDIUM] CVE-2002-0562: The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP store The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.
nvd
CVE-2002-0568LOWCVSS 2.1v1.0.22002-07-03
CVE-2002-0568 [LOW] CVE-2002-0568: Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
nvd
CVE-2001-1371HIGHCVSS 7.5v1.0.22002-02-06
CVE-2001-1371 [HIGH] CWE-264 CVE-2001-1371: The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymou The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
nvd
CVE-2001-1372MEDIUMCVSS 5.0v1.0.22002-02-06
CVE-2001-1372 [MEDIUM] CVE-2001-1372: Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file und Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.
nvd
CVE-2001-1216HIGHCVSS 7.5v1.0.22001-12-21
CVE-2001-1216 [HIGH] CVE-2001-1216: Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to e Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
nvd
CVE-2001-1217MEDIUMCVSS 5.0v1.0.22001-12-21
CVE-2001-1217 [MEDIUM] CVE-2001-1217: Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server all Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
nvd
CVE-2001-0591HIGHCVSS 7.5v1.0.22001-08-22
CVE-2001-0591 [HIGH] CVE-2001-0591: Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0 Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.
nvd
CVE-2001-0419HIGHCVSS 7.5PoCv4.0.8.22001-07-02
CVE-2001-0419 [HIGH] CVE-2001-0419: Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web lis Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute arbitrary commands via a long HTTP request that is passed to the application server, such as /jsp/.
nvd
CVE-2001-0326HIGHCVSS 7.5vrelease_1.0.2.0.12001-05-03
CVE-2001-0326 [HIGH] CVE-2001-0326: Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2 Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the > FilePermission.
nvd
CVE-2000-1236HIGHCVSS 7.5≤ 3.0.72000-12-31
CVE-2000-1236 [HIGH] CVE-2000-1236: SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
nvd
CVE-2000-1235MEDIUMCVSS 5.0≤ 3.0.72000-12-31
CVE-2000-1235 [MEDIUM] CVE-2000-1235: The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
nvd
CVE-2000-0169HIGHCVSS 7.5PoCv4.02000-03-15
CVE-2000-0169 [HIGH] CVE-2000-0169: Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'.
nvd