Oracle Application Server vulnerabilities
193 known vulnerabilities affecting oracle/application_server.
Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15
Vulnerabilities
Page 6 of 10
CVE-2007-5520P4HIGHCVSS 7.5v10.1.2.0.1v10.1.2.0.2+5 more2007-10-17
CVE-2007-5520 [HIGH] CVE-2007-5520: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8 and
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Database 9.2.0.8 and 9.2.0.8DV, and Oracle Application Server 9.0.4.3, 10.1.3.0.0 up to 10.1.3.3.0, and 10.1.2.0.1 up to 10.1.2.2.0, has unknown impact and remote attack vectors, aka AS05.
nvd
CVE-2007-3863P4HIGHCVSS 7.5v10.1.2.2v10.1.3.12007-07-18
CVE-2007-3863 [HIGH] CVE-2007-3863: Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Col
Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Collaboration Suite 10.1.2, allows context-dependent attackers to have an unknown impact via custom applications that use JBO.SERVER, aka JDEV02.
nvd
CVE-2002-0655P4HIGHCVSS 7.5v1.0.2v1.0.2.1s+1 more2002-08-12
CVE-2002-0655 [HIGH] CVE-2002-0655: OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representati
OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, does not properly handle ASCII representations of integers on 64 bit platforms, which could allow attackers to cause a denial of service and possibly execute arbitrary code.
nvd
CVE-2007-5525P4HIGHCVSS 7.5v9.0.4.3v10.1.2.0.2+2 more2007-10-17
CVE-2007-5525 [HIGH] CVE-2007-5525: Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.
Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0.1; Collaboration Suite 10.1.2; and Enterprise Manager 10.1.2 has unknown impact and remote attack vectors, aka AS10.
nvd
CVE-2002-2345P4HIGHCVSS 7.5v9.0.22002-12-31
CVE-2002-2345 [HIGH] CWE-255 CVE-2002-2345: Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintex
Oracle 9i Application Server 9.0.2 stores the web cache administrator interface password in plaintext, which allows remote attackers to gain access.
nvd
CVE-2005-3448P4CRITICALCVSS 10.0v9.0v9.0.2.3+6 more2005-11-02
CVE-2005-3448 [CRITICAL] CVE-2005-3448: Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has u
Unspecified vulnerability in the OC4J Module in Oracle Application Server 9.0 up to 10.1.2.0.2 has unknown impact and attack vectors, as identified by Oracle Vuln# AS01.
nvd
CVE-2007-3859P4HIGHCVSS 7.5v9.0.4.3v10.1.2.0.2+1 more2007-07-18
CVE-2007-3859 [HIGH] CVE-2007-3859: Unspecified vulnerability in the Oracle Internet Directory component for Oracle Database 9.2.0.8 and
Unspecified vulnerability in the Oracle Internet Directory component for Oracle Database 9.2.0.8 and 9.2.0.8DV; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 10.1.2 has unknown impact and remote attack vectors, aka OID01.
nvd
CVE-2007-2124P4CRITICALCVSS 10.0v10.1.4.1.02007-04-18
CVE-2007-2124 [CRITICAL] CVE-2007-2124: Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.4.1.0 has unknow
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.4.1.0 has unknown impact and remote attack vectors, aka AS05.
nvd
CVE-2007-2122P4CRITICALCVSS 10.0v9.0.4.32007-04-18
CVE-2007-2122 [CRITICAL] CVE-2007-2122: Unspecified vulnerability in the Wireless component in Oracle Application Server 9.0.4.3 has unknown
Unspecified vulnerability in the Wireless component in Oracle Application Server 9.0.4.3 has unknown impact and attack vectors, aka AS03.
nvd
CVE-2007-3861P4HIGHCVSS 7.5v10.1.2.22007-07-18
CVE-2007-3861 [HIGH] CVE-2007-3861: Unspecified vulnerability in Oracle Jdeveloper in Oracle Application Server 10.1.2.2 and Collaborati
Unspecified vulnerability in Oracle Jdeveloper in Oracle Application Server 10.1.2.2 and Collaboration Suite 10.1.2 allows context-dependent attackers to have an unknown impact via custom applications that use JBO.KEY, aka JDEV01.
nvd
CVE-2004-1365P4MEDIUMCVSS 4.6v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
CVE-2001-0591P4HIGHCVSS 7.5v1.0.22001-08-22
CVE-2001-0591 [HIGH] CVE-2001-0591: Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0
Directory traversal vulnerability in Oracle JSP 1.0.x through 1.1.1 and Oracle 8.1.7 iAS Release 1.0.2 can allow a remote attacker to read or execute arbitrary .jsp files via a '..' (dot dot) attack.
nvd
CVE-2007-2119P4MEDIUMCVSS 6.8v9.0.4.3v10.1.2.0.2+1 more2007-04-18
CVE-2007-2119 [MEDIUM] CVE-2007-2119: Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for O
Cross-site scripting (XSS) vulnerability in boundary_rules.jsp in the Administration Front End for Oracle Enterprise (Ultra) Search, as used in Database Server 9.2.0.8, 10.1.0.5, and 10.2.0.2, and in Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2.0 allows remote attackers to inject arbitrary HTML or web script via the EXPTYPE parameter, aka SES01.
nvd
CVE-2007-5518P4HIGHCVSS 7.5v10.1.3.2.02007-10-17
CVE-2007-5518 [HIGH] CVE-2007-5518: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 10.1.3.2
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 10.1.3.2 has unknown impact and remote attack vectors, aka AS03.
nvd
CVE-2007-5521P4HIGHCVSS 7.5v9.0.4.3v10.1.2.0.2+2 more2007-10-17
CVE-2007-5521 [HIGH] CVE-2007-5521: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.3.3, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS06.
nvd
CVE-2007-5523P4HIGHCVSS 7.5v9.0.4.3v10.1.2.0.2+2 more2007-10-17
CVE-2007-5523 [HIGH] CVE-2007-5523: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS08.
nvd
CVE-2006-0552P4HIGHCVSS 7.5v1.0.2.2v9.0.4+7 more2006-02-04
CVE-2006-0552 [HIGH] CVE-2006-0552: Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5,
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
nvd
CVE-2004-1366P4MEDIUMCVSS 4.6v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1366 [MEDIUM] CWE-255 CVE-2004-1366: Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-read
Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges.
nvd
CVE-2000-1236P4HIGHCVSS 7.5≤ 3.0.72000-12-31
CVE-2000-1236 [HIGH] CVE-2000-1236: SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
nvd
CVE-2007-5519P4HIGHCVSS 7.5v9.0.4.32007-10-17
CVE-2007-5519 [HIGH] CVE-2007-5519: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.0.2, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS04.
nvd