Oracle Application Server vulnerabilities
193 known vulnerabilities affecting oracle/application_server.
Total CVEs
193
CISA KEV
0
Public exploits
18
Exploited in wild
0
Severity breakdown
CRITICAL55HIGH49MEDIUM74LOW15
Vulnerabilities
Page 9 of 10
CVE-2006-3709P4MEDIUMCVSS 5.0v9.0.2.3v9.0.3.1+1 more2006-07-21
CVE-2006-3709 [MEDIUM] CVE-2006-3709: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 10.1.2.0.0 has
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 10.1.2.0.0 has unknown impact and attack vectors, aka Oracle Vuln# AS04.
nvd
CVE-2006-3706P4MEDIUMCVSS 5.0v9.0.2.32006-07-21
CVE-2006-3706 [MEDIUM] CVE-2006-3706: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 has unknown impact and attac
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3 has unknown impact and attack vectors, aka Oracle Vuln# AS01.
nvd
CVE-2001-1372P4MEDIUMCVSS 5.0v1.0.22002-02-06
CVE-2001-1372 [MEDIUM] CVE-2001-1372: Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file und
Oracle 9i Application Server 1.0.2 allows remote attackers to obtain the physical path of a file under the server root via a request for a non-existent .JSP file, which leaks the pathname in an error message.
nvd
CVE-2004-2244P4MEDIUMCVSS 5.0v1.0.2.2v1.0.2.2.2+2 more2004-12-31
CVE-2004-2244 [MEDIUM] CVE-2004-2244: The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, a
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
nvd
CVE-2009-0994P4MEDIUMCVSS 4.0v5.6.2v10.1.3.2.1+2 more2009-04-15
CVE-2009-0994 [MEDIUM] CVE-2009-0994: Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-1017.
nvd
CVE-2009-1017P4MEDIUMCVSS 4.0v5.6.2v10.1.3.2.1+2 more2009-04-15
CVE-2009-1017 [MEDIUM] CVE-2009-1017: Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-0994.
nvd
CVE-2009-0996P4MEDIUMCVSS 4.0v10.1.3.2.1v10.1.3.3.3+1 more2009-04-15
CVE-2009-0996 [MEDIUM] CVE-2009-0996: Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2002-2347P4MEDIUMCVSS 4.3v1.0.2v1.0.2.1s+2 more2002-12-31
CVE-2002-2347 [MEDIUM] CWE-79 CVE-2002-2347: Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.
Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.
nvd
CVE-2008-2593P4MEDIUMCVSS 4.3v10.1.2.3.0v10.1.4.2.02008-07-15
CVE-2008-2593 [MEDIUM] CVE-2008-2593: Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 1
Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2594.
nvd
CVE-2007-0285P4MEDIUMCVSS 5.0v9.0.4.3v10.1.2.0.2+1 more2007-01-17
CVE-2007-0285 [MEDIUM] CVE-2007-0285: Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaborat
Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.
nvd
CVE-2007-1609P4MEDIUMCVSS 4.3v10.1.2.0.02007-03-22
CVE-2007-1609 [MEDIUM] CVE-2007-1609: Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Orac
Cross-site scripting (XSS) vulnerability in servlet/Spy in Dynamic Monitoring Services (DMS) in Oracle Application Server (OAS) 10g 10.1.2.0.0 allows remote attackers to inject arbitrary web script or HTML via the table parameter. NOTE: This may be related to CVE-2002-0563.
nvd
CVE-2004-1877P4LOWCVSS 2.6v1.0.2v1.0.2.1s+10 more2004-03-30
CVE-2004-1877 [LOW] CVE-2004-1877: The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Si
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
nvd
CVE-2006-3711P4MEDIUMCVSS 4.0v9.0.2.3v9.0.3.1+1 more2006-07-21
CVE-2006-3711 [MEDIUM] CVE-2006-3711: Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 9.0.4.1 has un
Unspecified vulnerability in OC4J for Oracle Application Server 9.0.2.3, 9.0.3.1, and 9.0.4.1 has unknown impact and attack vectors, aka Oracle Vuln# AS06.
nvd
CVE-2008-2614P4MEDIUMCVSS 4.3v9.0.4.3v10.1.3.32008-07-15
CVE-2008-2614 [MEDIUM] CVE-2008-2614: Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 9.0.4.3,
Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.3.3 has unknown impact and remote attack vectors.
nvd
CVE-2006-3713P4MEDIUMCVSS 4.0v10.1.3.02006-07-21
CVE-2006-3713 [MEDIUM] CVE-2006-3713: Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and atta
Unspecified vulnerability in OC4J for Oracle Application Server 10.1.3.0 has unknown impact and attack vectors, aka Oracle Vuln# AS09.
nvd
CVE-2002-1636P4MEDIUMCVSS 4.3v1.0.22002-12-31
CVE-2002-1636 [MEDIUM] CVE-2002-1636: Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server
Cross-site scripting (XSS) vulnerability in the htp PL/SQL package for Oracle 9i Application Server (9iAS) allows remote attackers to inject arbitrary web script or HTML via the cbuf parameter to htp.print.
nvd
CVE-2009-1011P4MEDIUMCVSS 4.4v8.2.2v8.3.02009-04-15
CVE-2009-1011 [MEDIUM] CVE-2009-1011: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple inte
nvd
CVE-2009-1010P4MEDIUMCVSS 4.4v8.2.2v8.3.02009-04-15
CVE-2009-1010 [MEDIUM] CVE-2009-1010: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.
nvd
CVE-2009-1008P4MEDIUMCVSS 4.4v8.2.2v8.3.02009-04-15
CVE-2009-1008 [MEDIUM] CVE-2009-1008: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010.
nvd
CVE-2009-1009P4MEDIUMCVSS 4.4v8.1.92009-04-15
CVE-2009-1009 [MEDIUM] CVE-2009-1009: Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML.
nvd