Oracle Collaboration Suite vulnerabilities
62 known vulnerabilities affecting oracle/collaboration_suite.
Total CVEs
62
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH17MEDIUM11LOW6
Vulnerabilities
Page 2 of 4
CVE-2006-5361P4CRITICALCVSS 10.0v9.0.4.2v10.1.2.02006-10-18
CVE-2006-5361 [CRITICAL] CVE-2006-5361: Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2
Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.1, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J03.
nvd
CVE-2008-0344P4CRITICALCVSS 10.0v10.1.22008-01-17
CVE-2008-0344 [CRITICAL] CVE-2008-0344: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 h
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka DB07.
nvd
CVE-2008-0349P4CRITICALCVSS 10.0v10.1.22008-01-17
CVE-2008-0349 [CRITICAL] CVE-2008-0349: Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edward
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.
nvd
CVE-2008-0340P4CRITICALCVSS 10.0v10.1.22008-01-17
CVE-2008-0340 [CRITICAL] CVE-2008-0340: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote attack vectors, related to the (1) Advanced Queuing component (DB02) and (2) Oracle Spatial component (DB04).
nvd
CVE-2006-0282P4CRITICALCVSS 10.0v9.0.4.22006-01-18
CVE-2006-0282 [CRITICAL] CVE-2006-0282: Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.
Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.
nvd
CVE-2006-5348P4CRITICALCVSS 10.0v9.0.4.22006-10-18
CVE-2006-5348 [CRITICAL] CVE-2006-5348: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Ora
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.
nvd
CVE-2008-0345P4CRITICALCVSS 10.0v10.1.22008-01-17
CVE-2008-0345 [CRITICAL] CVE-2008-0345: Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact
Unspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.
nvd
CVE-2007-2130P4CRITICALCVSS 9.0v10.1.22007-04-18
CVE-2007-2130 [CRITICAL] CVE-2007-2130: Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2
Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.
nvd
CVE-2006-1884P4CRITICALCVSS 10.0v9.0.4.22006-04-20
CVE-2006-1884 [CRITICAL] CVE-2006-1884: Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business S
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
nvd
CVE-2006-5356P4CRITICALCVSS 10.0v9.0.4.2v10.1.2.02006-10-18
CVE-2006-5356 [CRITICAL] CVE-2006-5356: Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4
Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.1.0, and Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J02.
nvd
CVE-2007-0280P4HIGHCVSS 7.5v9.0.4.2v10.1.22007-01-17
CVE-2007-0280 [HIGH] CVE-2007-0280: Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.
Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OP
nvd
CVE-2006-3715P4CRITICALCVSS 10.0v10.1.22006-07-21
CVE-2006-3715 [CRITICAL] CVE-2006-3715: Unspecified vulnerability in Calendar for Oracle Collaboration Suite 10.1.2 has unknown impact and a
Unspecified vulnerability in Calendar for Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka Oracle Vuln# OCS01.
nvd
CVE-2008-0343P4CRITICALCVSS 10.0v10.1.22008-01-17
CVE-2008-0343 [CRITICAL] CVE-2008-0343: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8,
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.
nvd
CVE-2007-3864P4HIGHCVSS 7.5v10.1.22007-07-18
CVE-2007-3864 [HIGH] CVE-2007-3864: Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10.1.2 have unknown impact and re
Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10.1.2 have unknown impact and remote attack vectors via (1) Instant Messaging/Presence (OCS01) and (2) Oracle Single Sign On (AS02).
nvd
CVE-2007-3863P4HIGHCVSS 7.5v10.1.22007-07-18
CVE-2007-3863 [HIGH] CVE-2007-3863: Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Col
Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Collaboration Suite 10.1.2, allows context-dependent attackers to have an unknown impact via custom applications that use JBO.SERVER, aka JDEV02.
nvd
CVE-2007-5525P4HIGHCVSS 7.5v10.1.22007-10-17
CVE-2007-5525 [HIGH] CVE-2007-5525: Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.
Unspecified vulnerability in the Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.4.0.1; Collaboration Suite 10.1.2; and Enterprise Manager 10.1.2 has unknown impact and remote attack vectors, aka AS10.
nvd
CVE-2007-3859P4HIGHCVSS 7.5v10.1.22007-07-18
CVE-2007-3859 [HIGH] CVE-2007-3859: Unspecified vulnerability in the Oracle Internet Directory component for Oracle Database 9.2.0.8 and
Unspecified vulnerability in the Oracle Internet Directory component for Oracle Database 9.2.0.8 and 9.2.0.8DV; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 10.1.2 has unknown impact and remote attack vectors, aka OID01.
nvd
CVE-2007-3861P4HIGHCVSS 7.5v10.1.22007-07-18
CVE-2007-3861 [HIGH] CVE-2007-3861: Unspecified vulnerability in Oracle Jdeveloper in Oracle Application Server 10.1.2.2 and Collaborati
Unspecified vulnerability in Oracle Jdeveloper in Oracle Application Server 10.1.2.2 and Collaboration Suite 10.1.2 allows context-dependent attackers to have an unknown impact via custom applications that use JBO.KEY, aka JDEV01.
nvd
CVE-2004-1365P4MEDIUMCVSS 4.6vrelease_12004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
CVE-2007-5521P4HIGHCVSS 7.5v10.1.22007-10-17
CVE-2007-5521 [HIGH] CVE-2007-5521: Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.2, and 10.1.3.3, and Collaboration Suite 10.1.2, has unknown impact and remote attack vectors, aka AS06.
nvd