Oracle Application Server vulnerabilities
193 known vulnerabilities affecting oracle/application_server.
Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15
Vulnerabilities
Page 3 of 10
CVE-2008-1812P3CRITICALCVSS 10.0v9.0.4.32008-04-16
CVE-2008-1812 [CRITICAL] CVE-2008-1812: Unspecified vulnerability in the Oracle Enterprise Manager component in Oracle Database 9.0.1.5 FIPS
Unspecified vulnerability in the Oracle Enterprise Manager component in Oracle Database 9.0.1.5 FIPS+; Application Server 1.0.2.2; and Enterprise Manager for AS 1.0.2.2 and Database 9.0.1.5 has unknown impact and local attack vectors, aka EM01.
nvd
CVE-2002-2153P3HIGHCVSS 7.5v4.0.8v4.0.8.22002-12-31
CVE-2002-2153 [HIGH] CVE-2002-2153: Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application
Format string vulnerability in the administrative pages of the PL/SQL module for Oracle Application Server 4.0.8 and 4.0.8 2 allows remote attackers to execute arbitrary code.
nvd
CVE-2006-0291P3CRITICALCVSS 10.0v9.0.4.2v10.1.2.1.02006-01-18
CVE-2006-0291 [CRITICAL] CVE-2006-0291: Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2
Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.
nvd
CVE-2005-3445P3CRITICALCVSS 10.0v1.0.2.2v9.0.2.3+6 more2005-11-02
CVE-2005-3445 [CRITICAL] CVE-2005-3445: Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 an
Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05.
nvd
CVE-2006-5359P3CRITICALCVSS 10.0v9.0.4.3v10.1.2.0.22006-10-18
CVE-2006-5359 [CRITICAL] CVE-2006-5359: Multiple unspecified vulnerabilities in Oracle Reports Developer component in Oracle Application Ser
Multiple unspecified vulnerabilities in Oracle Reports Developer component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Oracle E-Business Suite and Applications 11.5.10CU2, have unknown impact and remote attack vectors, aka Vuln# (1) REP01 and (2) REP02. NOTE: as of 20061027, Oracle has not disputed reports from a reliable researcher that these
nvd
CVE-2008-1824P3CRITICALCVSS 10.0v9.0.4.3v10.1.2.2+1 more2008-04-16
CVE-2008-1824 [CRITICAL] CVE-2008-1824: Unspecified vulnerability in the Oracle Dynamic Monitoring Service component in Oracle Application S
Unspecified vulnerability in the Oracle Dynamic Monitoring Service component in Oracle Application Server 9.0.4.3, 10.1.2.2, and 10.1.3.3 has unknown impact and remote attack vectors, aka AS02.
nvd
CVE-2006-5353P3CRITICALCVSS 10.0v9.0.4.3v10.1.2.0.1+1 more2006-10-18
CVE-2006-5353 [CRITICAL] CVE-2006-5353: Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1
Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors related to the Mod_rewrite Module, aka Vuln# OHS01.
nvd
CVE-2006-5365P3CRITICALCVSS 10.0v9.0.4.3v10.1.2.0.22006-10-18
CVE-2006-5365 [CRITICAL] CVE-2006-5365: Unspecified vulnerability in Oracle Forms in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and E
Unspecified vulnerability in Oracle Forms in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors, aka Vuln# FORM02.
nvd
CVE-2002-1631P3HIGHCVSS 7.5v1.0.2v1.0.2.1s+3 more2002-12-31
CVE-2002-1631 [HIGH] CVE-2002-1631: SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) all
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
nvd
CVE-2002-0559P3HIGHCVSS 7.5v1.0.22002-07-03
CVE-2002-0559 [HIGH] CVE-2002-0559: Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote att
Buffer overflows in PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allow remote attackers to cause a denial of service or execute arbitrary code via (1) a long help page request without a dadname, which overflows the resulting HTTP Location header, (2) a long HTTP request to the plsql module, (3) a long password in the HTTP Authorization, (4) a
nvd
CVE-2006-0288P4CRITICALCVSS 10.0v9.0.4.12006-01-18
CVE-2006-0288 [CRITICAL] CVE-2006-0288: Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application
Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.
nvd
CVE-2008-1814P3CRITICALCVSS 9.0v9.0.4.3v10.1.2.22008-04-16
CVE-2008-1814 [CRITICAL] CVE-2008-1814: Unspecified vulnerability in the Oracle Secure Enterprise Search or Ultrasearch component in Oracle
Unspecified vulnerability in the Oracle Secure Enterprise Search or Ultrasearch component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3 and 10.1.2.2; and Oracle Collaboration Suite 10.1.2; has unknown impact and remote attack vectors, aka DB04.
nvd
CVE-2006-0284P4CRITICALCVSS 10.0v9.0.4.2v10.1.2.0.22006-01-18
CVE-2006-0284 [CRITICAL] CVE-2006-0284: Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Busi
Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.2 and 10.1.2.0.2, and E-Business Suite and Applications 11.5.10, have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) FORM01 and (2) FORM02 in the Oracle Forms component.
nvd
CVE-2006-0290P4CRITICALCVSS 10.0v9.0.4.2v10.1.2.12006-01-18
CVE-2006-0290 [CRITICAL] CVE-2006-0290: Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1
Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.
nvd
CVE-2006-5355P4CRITICALCVSS 10.0v9.0.4.3v10.1.2.0.2+1 more2006-10-18
CVE-2006-5355 [CRITICAL] CVE-2006-5355: Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 1
Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.1.0, Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# SSO01.
nvd
CVE-2006-5357P4CRITICALCVSS 10.0v10.1.2.0.1v10.1.2.0.2+1 more2006-10-18
CVE-2006-5357 [CRITICAL] CVE-2006-5357: Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 1
Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 10.1.2.0.2, and 10.1.2.1.0 has unknown impact and remote attack vectors related to the PHP Module, aka Vuln# OHS03.
nvd
CVE-2008-0346P3CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0346 [CRITICAL] CVE-2008-0346: Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 a
Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.
nvd
CVE-2007-5526P3CRITICALCVSS 10.0v10.1.2.0.2v10.1.2.2+1 more2007-10-17
CVE-2007-5526 [CRITICAL] CVE-2007-5526: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2, 10
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2, 10.1.2.2, and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS11.
nvd
CVE-2007-0275P4LOWCVSS 3.5PoCv9.0.4.3v10.1.2.0.2+1 more2007-01-17
CVE-2007-0275 [LOW] CWE-79 CVE-2007-0275: Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow C
Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to i
nvd
CVE-2006-0283P4CRITICALCVSS 10.0v10.1.2.0.22006-01-18
CVE-2006-0283 [CRITICAL] CVE-2006-0283: Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and C
Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects & Convert Tablespace component.
nvd