cbcvebase.

Oracle Application Server vulnerabilities

193 known vulnerabilities affecting oracle/application_server.

Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15

Vulnerabilities

Page 7 of 10
CVE-2007-5516P4HIGHCVSS 7.5v10.1.3.32007-10-17
CVE-2007-5516 [HIGH] CVE-2007-5516: Unspecified vulnerability in the Oracle Process Mgmt & Notification component in Oracle Application Unspecified vulnerability in the Oracle Process Mgmt & Notification component in Oracle Application Server 10.1.3.3 has unknown impact and remote attack vectors, aka AS01.
nvd
CVE-2007-5524P4HIGHCVSS 7.5v9.0.4.3v10.1.2.0.2+1 more2007-10-17
CVE-2007-5524 [HIGH] CVE-2007-5524: Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4. Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS09 or AS9.
nvd
CVE-2007-5522P4HIGHCVSS 7.5v10.1.4.12007-10-17
CVE-2007-5522 [HIGH] CVE-2007-5522: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.4.1 has u Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.4.1 has unknown impact and remote attack vectors, aka AS07.
nvd
CVE-2007-5517P4HIGHCVSS 7.5v10.1.2.0.2v10.1.4.12007-10-17
CVE-2007-5517 [HIGH] CVE-2007-5517: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2 and Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.0.2 and 10.1.4.1, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS02.
nvd
CVE-2002-0562P4MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0562 [MEDIUM] CVE-2002-0562: The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP store The default configuration of Oracle 9i Application Server 1.0.2.x running Oracle JSP or SQLJSP stores globals.jsa under the web root, which allows remote attackers to gain sensitive information including usernames and passwords via a direct HTTP request to globals.jsa.
nvd
CVE-2006-0275P4MEDIUMCVSS 5.0v9.0.4.22006-01-18
CVE-2006-0275 [MEDIUM] CVE-2006-0275: Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0 Unspecified vulnerability in the Oracle Reports Developer component of Oracle Application Server 9.0.4.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# REP04. NOTE: Oracle has not disputed reliable researcher claims that this issue is related to directory traversal that allows reading of portions of arbitrary XML files via the custom
nvd
CVE-2007-3854P4MEDIUMCVSS 5.5v1.0.2.2v9.0.4.3+8 more2007-07-18
CVE-2007-3854 [MEDIUM] CVE-2007-3854: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is
nvd
CVE-2005-1495P4HIGHCVSS 7.5v10.1.0.2v10.1.0.3+1 more2005-05-11
CVE-2005-1495 [HIGH] CVE-2005-1495: Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT st Oracle Database 9i and 10g disables Fine Grained Audit (FGA) after the SYS user executes a SELECT statement on an FGA object, which makes it easier for attackers to escape detection.
nvd
CVE-2008-7235P4MEDIUMCVSS 4.3v10.1.2.22009-09-14
CVE-2008-7235 [MEDIUM] CVE-2008-7235: Unspecified vulnerability in the Oracle Forms component in Oracle Application Server 10.1.2.2 and E- Unspecified vulnerability in the Oracle Forms component in Oracle Application Server 10.1.2.2 and E-Business Suite 12.0.3 allows remote attackers to affect integrity via unknown vectors, aka AS04.
nvd
CVE-2010-0066P4MEDIUMCVSS 5.0v7.0.4.3v10.1.4.22010-01-13
CVE-2010-0066 [MEDIUM] CVE-2010-0066: Unspecified vulnerability in the Access Manager Identity Server component in Oracle Application Serv Unspecified vulnerability in the Access Manager Identity Server component in Oracle Application Server 7.0.4.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2009-0989P4MEDIUMCVSS 5.5v5.6.2v10.1.3.2.1+1 more2009-04-15
CVE-2009-0989 [MEDIUM] CVE-2009-0989: Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2 Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0990.
nvd
CVE-2009-0990P4MEDIUMCVSS 5.5v5.6.2v10.1.3.2.1+1 more2009-04-15
CVE-2009-0990 [MEDIUM] CVE-2009-0990: Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2 Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0989.
nvd
CVE-2008-7236P4MEDIUMCVSS 4.3v10.1.2.2v10.1.3.12009-09-14
CVE-2008-7236 [MEDIUM] CVE-2008-7236: Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 a Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 and 10.1.3.1 allows remote attackers to affect integrity via unknown vectors, aka AS05.
nvd
CVE-2010-0067P4MEDIUMCVSS 5.0v10.1.2.3v10.1.3.42010-01-13
CVE-2010-0067 [MEDIUM] CVE-2010-0067: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 1 Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2009-3407P4MEDIUMCVSS 4.3v10.1.2.3v10.1.4.22009-10-22
CVE-2009-3407 [MEDIUM] CVE-2009-3407: Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-0983.
nvd
CVE-2008-2609P4MEDIUMCVSS 6.4v9.0.4.32008-07-15
CVE-2008-2609 [MEDIUM] CVE-2008-2609: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3, 10.1. Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors.
nvd
CVE-2002-1858P4MEDIUMCVSS 5.0v1.0.2.2v9.0.2+2 more2002-12-31
CVE-2002-1858 [MEDIUM] CVE-2002-1858: Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, all Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
nvd
CVE-2005-2093P4MEDIUMCVSS 4.3v9.0.22005-07-05
CVE-2005-2093 [MEDIUM] CVE-2005-2093: Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, byp Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way
nvd
CVE-2009-0974P4MEDIUMCVSS 4.3v10.1.2.3.0v10.1.4.2.02009-04-15
CVE-2009-0974 [MEDIUM] CVE-2009-0974: Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0983 and CVE-2009-3407.
nvd
CVE-2002-0565P4MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0565 [MEDIUM] CVE-2002-0565: Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under Oracle 9iAS 1.0.2.x compiles JSP files in the _pages directory with world-readable permissions under the web root, which allows remote attackers to obtain sensitive information derived from the JSP code, including usernames and passwords, via a direct HTTP request to _pages.
nvd
Oracle Application Server vulnerabilities | cvebase