Oracle Application Server vulnerabilities
193 known vulnerabilities affecting oracle/application_server.
Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15
Vulnerabilities
Page 6 of 10
CVE-2006-5363LOWCVSS 2.6v10.1.2.0.12006-10-18
CVE-2006-5363 [LOW] CVE-2006-5363: Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 10.1.2.0.1
Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 10.1.2.0.1 and Collaboration Suite 10.1.2 has unknown impact and remote attack vectors, aka Vuln# SSO02.
nvd
CVE-2006-5364LOWCVSS 2.1v9.0.4.1v10.1.2.0.22006-10-18
CVE-2006-5364 [LOW] CVE-2006-5364: Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4
Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4.1 and 10.1.2.0.2, and Collaboration Suite 10.1.2, has unknown impact and remote authenticated attack vectors, aka Vuln# OC4J05.
nvd
CVE-2006-3708CRITICALCVSS 10.0v9.0.2.3v9.0.3.1+3 more2006-07-21
CVE-2006-3708 [CRITICAL] CVE-2006-3708: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, 10.1.2.0.
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, 10.1.2.0.2, and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS03.
nvd
CVE-2006-3710CRITICALCVSS 10.0v9.0.2.3v9.0.3.1+2 more2006-07-21
CVE-2006-3710 [CRITICAL] CVE-2006-3710: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, and 10.1.
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, 9.0.4.2, and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# (1) AS05 and (2) AS08.
nvd
CVE-2006-3709MEDIUMCVSS 5.0v9.0.2.3v9.0.3.1+1 more2006-07-21
CVE-2006-3709 [MEDIUM] CVE-2006-3709: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 10.1.2.0.0 has
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS04.
nvd
CVE-2006-3706MEDIUMCVSS 5.0v9.0.2.32006-07-21
CVE-2006-3706 [MEDIUM] CVE-2006-3706: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 has unknown impact and attac
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 has unknown impact and attack vectors, aka Oracle Vuln# AS01.
nvd
CVE-2006-3714MEDIUMCVSS 5.0v10.1.2.0.2v10.1.2.12006-07-21
CVE-2006-3714 [MEDIUM] CVE-2006-3714: Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS10.
nvd
CVE-2006-3712MEDIUMCVSS 5.0v9.0.4.2v10.1.2.0.02006-07-21
CVE-2006-3712 [MEDIUM] CVE-2006-3712: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown i
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.
nvd
CVE-2006-3713MEDIUMCVSS 4.0v10.1.3.02006-07-21
CVE-2006-3713 [MEDIUM] CVE-2006-3713: Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and atta
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and attack vectors, aka Oracle Vuln# AS09.
nvd
CVE-2006-3711MEDIUMCVSS 4.0v9.0.2.3v9.0.3.1+1 more2006-07-21
CVE-2006-3711 [MEDIUM] CVE-2006-3711: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 9.0.4.1 has un
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 9.0.4.1 has unknown impact and attack vectors, aka Oracle Vuln# AS06.
nvd
CVE-2006-3707LOWCVSS 3.6v9.0.2.3v9.0.3.12006-07-21
CVE-2006-3707 [LOW] CVE-2006-3707: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 and 9.0.3.1 has unknown impa
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 and 9.0.3.1 has unknown impact and attack vectors, aka Oracle Vuln# AS02.
nvd
CVE-2006-1884CRITICALCVSS 10.0v1.0.2.2v9.0.4.1+6 more2006-04-20
CVE-2006-1884 [CRITICAL] CVE-2006-1884: Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business S
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
nvd
CVE-2006-0586HIGHCVSS 7.5PoCv10.1.0.2v10.1.0.3+6 more2006-02-08
CVE-2006-0586 [HIGH] CWE-89 CVE-2006-0586: Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote atta
Multiple SQL injection vulnerabilities in Oracle 10g Release 1 before CPU Jan 2006 allow remote attackers to execute arbitrary SQL commands via multiple parameters in (1) ATTACH_JOB, (2) HAS_PRIVS, and (3) OPEN_JOB functions in the SYS.KUPV$FT package; and (4) UPDATE_JOB, (5) ACTIVE_JOB, (6) ATTACH_POSSIBLE, (7) ATTACH_TO_JOB, (8) CREATE_NEW_JOB, (9) DEL
nvd
CVE-2006-0552HIGHCVSS 7.5v1.0.2.2v9.0.4+7 more2006-02-04
CVE-2006-0552 [HIGH] CVE-2006-0552: Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5,
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
nvd
CVE-2006-0435HIGHCVSS 7.5v1.0.2v1.0.2.0+25 more2006-01-26
CVE-2006-0435 [HIGH] CVE-2006-0435: Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0
Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded pac
nvd
CVE-2006-0286CRITICALCVSS 10.0v1.0.2.2v9.0.4.2+1 more2006-01-18
CVE-2006-0286 [CRITICAL] CVE-2006-0286: Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, and Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS01.
nvd
CVE-2006-0273CRITICALCVSS 10.0v9.0.4.2v10.1.2.02006-01-18
CVE-2006-0273 [CRITICAL] CVE-2006-0273: Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0
Unspecified vulnerability in the Portal component of Oracle Application Server 9.0.4.2 and 10.1.2.0 has unspecified impact and attack vectors, as identified by Oracle Vuln# AS01.
nvd
CVE-2006-0274CRITICALCVSS 10.0v9.0.4.2v10.1.2.0.22006-01-18
CVE-2006-0274 [CRITICAL] CVE-2006-0274: Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0
Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 and 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP03.
nvd
CVE-2006-0288CRITICALCVSS 10.0v9.0.4.12006-01-18
CVE-2006-0288 [CRITICAL] CVE-2006-0288: Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application
Multiple unspecified vulnerabilities in the Oracle Reports Developer component of Oracle Application Server 9.0.4.1 and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) REP01 and (2) REP02.
nvd
CVE-2006-0287CRITICALCVSS 10.0PoCv10.1.2.0.22006-01-18
CVE-2006-0287 [CRITICAL] CVE-2006-0287: Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and
Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.
nvd