Oracle Application Server vulnerabilities
193 known vulnerabilities affecting oracle/application_server.
Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15
Vulnerabilities
Page 8 of 10
CVE-2007-0289P4MEDIUMCVSS 6.4v9.0.4.22007-01-17
CVE-2007-0289 [MEDIUM] CVE-2007-0289: Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and a
Multiple unspecified vulnerabilities in Oracle Collaboration Suite 9.0.4.2 have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J01, (2) OC4J05, and (3) OC4J06.
nvd
CVE-2007-0284P4MEDIUMCVSS 6.4v9.0.4.3v10.1.2.0.02007-01-17
CVE-2007-0284 [MEDIUM] CVE-2007-0284: Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collab
Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.
nvd
CVE-2000-1235P4MEDIUMCVSS 5.0≤ 3.0.72000-12-31
CVE-2000-1235 [MEDIUM] CVE-2000-1235: The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
nvd
CVE-2008-4014P4MEDIUMCVSS 5.5v1.0v1.0.2+57 more2009-01-14
CVE-2008-4014 [MEDIUM] CVE-2008-4014: Unspecified vulnerability in the Oracle BPEL Process Manager component in Oracle Application Server
Unspecified vulnerability in the Oracle BPEL Process Manager component in Oracle Application Server allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2008-7237P4MEDIUMCVSS 4.0v9.0.4.3v10.1.2.22009-09-14
CVE-2008-7237 [MEDIUM] CVE-2008-7237: Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3 and 10.1.2.2 allows remote authenticated users to affect confidentiality via unknown vectors, aka AS06.
nvd
CVE-2008-3977P4MEDIUMCVSS 5.0v9.0.4.3v10.1.2.32008-10-14
CVE-2008-3977 [MEDIUM] CVE-2008-3977: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3975.
nvd
CVE-2008-3975P4MEDIUMCVSS 5.0v9.0.4.3v10.1.2.32008-10-14
CVE-2008-3975 [MEDIUM] CVE-2008-3975: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3977.
nvd
CVE-2008-4017P4MEDIUMCVSS 5.0v10.1.2.32009-01-14
CVE-2008-4017 [MEDIUM] CVE-2008-4017: Unspecified vulnerability in the OC4J component in Oracle Application Server 10.1.2.3 allows remote
Unspecified vulnerability in the OC4J component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2009-0983P4MEDIUMCVSS 4.3v10.1.2.3.0v10.1.4.2.02009-04-15
CVE-2009-0983 [MEDIUM] CVE-2009-0983: Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-3407.
nvd
CVE-2004-1369P4MEDIUMCVSS 5.0v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1369 [MEDIUM] CVE-2004-1369: The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash)
The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that references incorrect memory.
nvd
CVE-2002-0566P4MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0566 [MEDIUM] CVE-2002-0566: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a d
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to cause a denial of service (crash) via an HTTP Authorization header without an authentication type.
nvd
CVE-2002-1632P4MEDIUMCVSS 6.4v1.0.2v1.0.2.1s+3 more2002-12-31
CVE-2002-1632 [MEDIUM] CVE-2002-1632: Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to ob
Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
nvd
CVE-2007-0281P4MEDIUMCVSS 5.0v9.0.4.3v10.1.2.0.2+1 more2007-01-17
CVE-2007-0281 [MEDIUM] CVE-2007-0281: Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3;
Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.
nvd
CVE-2008-5438P4MEDIUMCVSS 4.3v10.1.2.3.0v10.1.4.2.02009-01-14
CVE-2008-5438 [MEDIUM] CVE-2008-5438: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 1
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2010-0070P4MEDIUMCVSS 4.3v10.1.2.3v10.1.3.42010-01-13
CVE-2010-0070 [MEDIUM] CVE-2010-0070: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 1
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2006-3712P4MEDIUMCVSS 5.0v9.0.4.2v10.1.2.0.02006-07-21
CVE-2006-3712 [MEDIUM] CVE-2006-3712: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown i
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.4.2 and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS07.
nvd
CVE-2006-3714P4MEDIUMCVSS 5.0v10.1.2.0.2v10.1.2.12006-07-21
CVE-2006-3714 [MEDIUM] CVE-2006-3714: Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.2.0.2 and 10.1.2.1 has unknown impact and attack vectors, aka Oracle Vuln# AS10.
nvd
CVE-2002-0560P4MEDIUMCVSS 5.0v1.0.22002-07-03
CVE-2002-0560 [MEDIUM] CVE-2002-0560: PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain se
PL/SQL module 3.0.9.8.2 in Oracle 9i Application Server 1.0.2.x allows remote attackers to obtain sensitive information via the OWA_UTIL stored procedures (1) OWA_UTIL.signature, (2) OWA_UTIL.listprint, or (3) OWA_UTIL.show_query_columns.
nvd
CVE-2004-1367P4MEDIUMCVSS 4.4v9.0.2v9.0.2.0.0+9 more2004-08-04
CVE-2004-1367 [MEDIUM] CWE-200 CVE-2004-1367: Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!")
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed
nvd
CVE-2009-1976P4MEDIUMCVSS 4.3v10.1.2.32009-07-14
CVE-2009-1976 [MEDIUM] CVE-2009-1976: Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows
Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.
nvd