cbcvebase.

Oracle Application Server vulnerabilities

193 known vulnerabilities affecting oracle/application_server.

Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15

Vulnerabilities

Page 4 of 10
CVE-2004-1368P4HIGHCVSS 7.8v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1368 [HIGH] CVE-2004-1368: ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.
nvd
CVE-2006-0285P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.2+1 more2006-01-18
CVE-2006-0285 [CRITICAL] CVE-2006-0285: Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0. Unspecified vulnerability in the Java Net component of Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.4, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# JN01.
nvd
CVE-2006-0286P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.2+1 more2006-01-18
CVE-2006-0286 [CRITICAL] CVE-2006-0286: Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0 Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.
nvd
CVE-2009-0217P3MEDIUMCVSS 5.0v10.1.2.3v10.1.3.4+1 more2009-07-14
CVE-2009-0217 [MEDIUM] CVE-2009-0217: The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented i The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.
nvd
CVE-2006-3708P4CRITICALCVSS 10.0v9.0.2.3v9.0.3.1+3 more2006-07-21
CVE-2006-3708 [CRITICAL] CVE-2006-3708: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, 10.1.2.0. Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, 10.1.2.0.2, and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS03.
nvd
CVE-2006-5361P4CRITICALCVSS 10.0v9.0.4.3v10.1.2.0.2+1 more2006-10-18
CVE-2006-5361 [CRITICAL] CVE-2006-5361: Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2 Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.1, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J03.
nvd
CVE-2008-0344P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0344 [CRITICAL] CVE-2008-0344: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 h Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.
nvd
CVE-2008-0349P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0349 [CRITICAL] CVE-2008-0349: Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edward Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.
nvd
CVE-2008-0340P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0340 [CRITICAL] CVE-2008-0340: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).
nvd
CVE-2002-0568P4LOWCVSS 2.1v1.0.22002-07-03
CVE-2002-0568 [LOW] CVE-2002-0568: Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requesting (1) XSQLConfig.xml or (2) soapConfig.xml through a virtual directory.
nvd
CVE-2006-0282P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.2+1 more2006-01-18
CVE-2006-0282 [CRITICAL] CVE-2006-0282: Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10. Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.
nvd
CVE-2005-3451P4CRITICALCVSS 10.0v9.0v9.0.2.12005-11-02
CVE-2005-3451 [CRITICAL] CVE-2005-3451: Unspecified vulnerability in SQL*ReportWriter in Oracle Application Server 9.0 up to 9.0.2.1 has unk Unspecified vulnerability in SQL*ReportWriter in Oracle Application Server 9.0 up to 9.0.2.1 has unknown impact and attack vectors, as identified by Oracle Vuln# AS10.
nvd
CVE-2005-3453P4CRITICALCVSS 10.0v1.0v1.0.2.2+6 more2005-11-02
CVE-2005-3453 [CRITICAL] CVE-2005-3453: Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 ha Multiple unspecified vulnerabilities in Web Cache in Oracle Application Server 1.0 up to 10.1.2.0 has unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS12 and (2) AS14.
nvd
CVE-2004-2134P4MEDIUMCVSS 4.6PoCv9.0.2v9.0.2.0.0+5 more2004-01-28
CVE-2004-2134 [MEDIUM] CVE-2004-2134: Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the passwords.
nvd
CVE-2008-0345P4CRITICALCVSS 10.0v1.0.2.2v9.0.4.3+6 more2008-01-17
CVE-2008-0345 [CRITICAL] CVE-2008-0345: Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.
nvd
CVE-2007-3862P3HIGHCVSS 7.5v9.0.4.3v10.1.2.0.22007-07-18
CVE-2007-3862 [HIGH] CVE-2007-3862: Unspecified vulnerability in Oracle Application Server 9.0.4.3 and 10.1.2.0.2 allows remote attacker Unspecified vulnerability in Oracle Application Server 9.0.4.3 and 10.1.2.0.2 allows remote attackers to have an unknown impact via Oracle Single Sign On, aka AS01.
nvd
CVE-2018-0735P4MEDIUMCVSS 5.9v0.9.8v1.0.0+1 more2018-10-29
CVE-2018-0735 [MEDIUM] CWE-327 CVE-2018-0735: The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attac The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).
nvd
CVE-2001-1371P4HIGHCVSS 7.5v1.0.22002-02-06
CVE-2001-1371 [HIGH] CWE-264 CVE-2001-1371: The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymou The default configuration of Oracle Application Server 9iAS 1.0.2.2 enables SOAP and allows anonymous users to deploy applications by default via urn:soap-service-manager and urn:soap-provider-manager.
nvd
CVE-2007-2130P4CRITICALCVSS 9.0v9.0.4.3v10.1.2.0.22007-04-18
CVE-2007-2130 [CRITICAL] CVE-2007-2130: Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2 Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.
nvd
CVE-2005-3449P4CRITICALCVSS 10.0v9.0v9.0.2.3+6 more2005-11-02
CVE-2005-3449 [CRITICAL] CVE-2005-3449: Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown im Multiple unspecified vulnerabilities in Oracle Application Server 9.0 up to 10.1.2.0 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) AS02 in Containers for J2EE, (2) AS07 in Internet Directory, (3) AS09 in Report Server, and (4) AS11 in Web Cache.
nvd
Oracle Application Server vulnerabilities | cvebase