cbcvebase.

Oracle Application Server vulnerabilities

193 known vulnerabilities affecting oracle/application_server.

Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15

Vulnerabilities

Page 2 of 10
CVE-2002-0561P3HIGHCVSS 7.5v1.0.22002-07-03
CVE-2002-0561 [HIGH] CVE-2002-0561: The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Applicatio The default configuration of the PL/SQL Gateway web administration interface in Oracle 9i Application Server 1.0.2.x uses null authentication, which allows remote attackers to gain privileges and modify DAD settings.
nvd
CVE-2002-0843P3HIGHCVSS 7.5v1.0.2v1.0.2.1s+3 more2002-10-11
CVE-2002-0843 [HIGH] CVE-2002-0843: Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Ap Buffer overflows in the ApacheBench benchmark support program (ab.c) in Apache before 1.3.27, and Apache 2.x before 2.0.43, allow a malicious web server to cause a denial of service and possibly execute arbitrary code via a long response.
nvd
CVE-2002-0842P3HIGHCVSS 7.5v9.0.22003-03-03
CVE-2002-0842 [HIGH] CVE-2002-0842: Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway Format string vulnerability in certain third party modifications to mod_dav for logging bad gateway messages (e.g. Oracle9i Application Server 9.0.2) allows remote attackers to execute arbitrary code via a destination URI that forces a "502 Bad Gateway" response, which causes the format string specifiers to be returned from dav_lookup_uri() in mod_dav.c, which i
nvd
CVE-2006-0289P3CRITICALCVSS 10.0v6.0.8.26_ps172006-01-18
CVE-2006-0289 [CRITICAL] CVE-2006-0289: Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suit Multiple unspecified vulnerabilities in Oracle Application Server 6.0.8.26(PS17) and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP05 and (2) REP06 in the Oracle Reports Developer component. NOTE: Oracle has not disputed reliable researcher claims that REP05 is the same as CVE-2005
nvd
CVE-2002-1089P4MEDIUMCVSS 5.0PoCv9.0.22002-10-04
CVE-2002-1089 [MEDIUM] CVE-2002-1089: rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.
nvd
CVE-2005-1496P3MEDIUMCVSS 4.6v10.1.0.2v10.1.0.3+1 more2005-05-11
CVE-2005-1496 [MEDIUM] CVE-2005-1496: The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain addition The DBMS_Scheduler in Oracle 10g allows remote attackers with CREATE JOB privileges to gain additional privileges by changing SESSION_USER to the SYS user.
nvd
CVE-2006-5354P3CRITICALCVSS 10.0v9.0.4.3v10.1.2.0.2+1 more2006-10-18
CVE-2006-5354 [CRITICAL] CVE-2006-5354: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10 Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06.
nvd
CVE-2001-1217P4MEDIUMCVSS 5.0v1.0.22001-12-21
CVE-2001-1217 [MEDIUM] CVE-2001-1217: Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server all Directory traversal vulnerability in PL/SQL Apache module in Oracle Oracle 9i Application Server allows remote attackers to access sensitive information via a double encoded URL with .. (dot dot) sequences.
nvd
CVE-2007-3553P4MEDIUMCVSS 4.3PoCv11i2007-07-03
CVE-2007-3553 [MEDIUM] CVE-2007-3553: Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11 Cross-site scripting (XSS) vulnerability in Rapid Install Web Server in Oracle Application Server 11i allows remote attackers to inject arbitrary web script or HTML via a URL to the "Secondary Login Page", as demonstrated using (1) pls/ and (2) pls/MSBEP004/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party
nvd
CVE-2004-1362P3HIGHCVSS 7.5v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1362 [HIGH] CVE-2004-1362: The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
nvd
CVE-2008-0347P3CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0347 [CRITICAL] CVE-2008-0347: Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01. NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.
nvd
CVE-2006-0435P3HIGHCVSS 7.5v1.0.2v1.0.2.0+25 more2006-01-26
CVE-2006-0435 [HIGH] CVE-2006-0435: Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0 Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded pac
nvd
CVE-2002-0564P3HIGHCVSS 7.5v1.0.22002-07-03
CVE-2002-0564 [HIGH] CVE-2002-0564: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass au PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to bypass authentication for a Database Access Descriptor (DAD) by modifying the URL to reference an alternate DAD that already has valid credentials.
nvd
CVE-2004-1370P3HIGHCVSS 7.5v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1370 [HIGH] CVE-2004-1370: Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9 Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
nvd
CVE-2008-7234P3MEDIUMCVSS 6.8v10.1.2.2v10.1.3.32009-09-14
CVE-2008-7234 [MEDIUM] CVE-2008-7234: Unspecified vulnerability in the Oracle BPEL Worklist Application component in Oracle Application Se Unspecified vulnerability in the Oracle BPEL Worklist Application component in Oracle Application Server 10.1.2.2 and 10.1.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, aka AS03.
nvd
CVE-2007-2120P3HIGHCVSS 7.8v9.0.4.3v10.1.2.0.2+1 more2007-04-18
CVE-2007-2120 [HIGH] CWE-399 CVE-2007-2120: The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allow The Oracle Discoverer servlet in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to shut down an Oracle TNS Listener via a TNS STOP command in a request that uses the database/TNS alias, aka AS01.
nvd
CVE-2002-0947P3HIGHCVSS 7.5v9.0.22002-10-04
CVE-2002-0947 [HIGH] CVE-2002-0947: Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products, allows remote attackers to execute arbitrary code via a long database name parameter.
nvd
CVE-2008-0348P3CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0348 [CRITICAL] CVE-2008-0348: Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise an Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.
nvd
CVE-2004-1363P3CRITICALCVSS 9.8v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1363 [CRITICAL] CWE-131 CVE-2004-1363: Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via envir Buffer overflow in extproc in Oracle 10g allows remote attackers to execute arbitrary code via environment variables in the library name, which are expanded after the length check is performed.
nvd
CVE-2001-1216P3HIGHCVSS 7.5v1.0.22001-12-21
CVE-2001-1216 [HIGH] CVE-2001-1216: Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to e Buffer overflow in PL/SQL Apache module in Oracle 9i Application Server allows remote attackers to execute arbitrary code via a long request for a help page.
nvd
Oracle Application Server vulnerabilities | cvebase