Oracle Collaboration Suite vulnerabilities

62 known vulnerabilities affecting oracle/collaboration_suite.

Total CVEs
62
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH17MEDIUM11LOW6

Vulnerabilities

Page 2 of 4
CVE-2007-3864HIGHCVSS 7.5v10.1.22007-07-18
CVE-2007-3864 [HIGH] CVE-2007-3864: Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10.1.2 have unknown impact and re Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10.1.2 have unknown impact and remote attack vectors via (1) Instant Messaging/Presence (OCS01) and (2) Oracle Single Sign On (AS02).
nvd
CVE-2007-3863HIGHCVSS 7.5v10.1.22007-07-18
CVE-2007-3863 [HIGH] CVE-2007-3863: Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Col Unspecified vulnerability in Oracle JDeveloper for Application Server 10.1.2.2 and 10.1.3.1, and Collaboration Suite 10.1.2, allows context-dependent attackers to have an unknown impact via custom applications that use JBO.SERVER, aka JDEV02.
nvd
CVE-2007-3854MEDIUMCVSS 5.5v10.1.22007-07-18
CVE-2007-3854 [MEDIUM] CVE-2007-3854: Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote Multiple unspecified vulnerabilities in Oracle Database 9.0.1.5+, 9.2.0.7, and 10.1.0.5 allow remote authenticated users to have unknown impact via (1) SYS.DBMS_PRVTAQIS in the Advanced Queuing component (DB02) and (2) MDSYS.MD in the Spatial component (DB12). NOTE: Oracle has not disputed reliable researcher claims that DB02 is for SQL injection and DB12 is
nvd
CVE-2007-2130CRITICALCVSS 9.0v10.1.22007-04-18
CVE-2007-2130 [CRITICAL] CVE-2007-2130: Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2 Unspecified vulnerability in Workflow Cartridge, as used in Oracle Database Server 9.2.0.1, 10.1.0.2, and 10.2.0.1; Application Server 9.0.4.3 and 10.1.2.0.2; Collaboration Suite 10.1.2; and E-Business Suite; has unknown impact and remote authenticated attack vectors, aka OWF01.
nvd
CVE-2007-2125CRITICALCVSS 10.0v10.1.22007-04-18
CVE-2007-2125 [CRITICAL] CVE-2007-2125: Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknow Unspecified vulnerability in Collaborative Workspace in Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka OCS01.
nvd
CVE-2007-0280HIGHCVSS 7.5v9.0.4.2v10.1.22007-01-17
CVE-2007-0280 [HIGH] CVE-2007-0280: Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10. Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.2, and 10.1.2.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN01. NOTE: as of 20070123, Oracle has not disputed claims by a reliable researcher that OP
nvd
CVE-2007-0284MEDIUMCVSS 6.4v9.0.4.22007-01-17
CVE-2007-0284 [MEDIUM] CVE-2007-0284: Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collab Multiple unspecified vulnerabilities in Oracle Application Server 9.0.4.3 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2, have unknown impact and attack vectors related to Oracle Containers for J2EE, aka (1) OC4J03 and (2) OC4J04.
nvd
CVE-2007-0285MEDIUMCVSS 5.0v9.0.4.2v10.1.22007-01-17
CVE-2007-0285 [MEDIUM] CVE-2007-0285: Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaborat Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 9.0.4.2 and 10.1.2; and E-Business Suite and Applications 11.5.10CU2 has unknown impact and attack vectors related to Oracle Reports Developer, aka REP01.
nvd
CVE-2007-0283MEDIUMCVSS 4.0v9.0.4.22007-01-17
CVE-2007-0283 [MEDIUM] CVE-2007-0283: Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has u Unspecified vulnerability in Oracle Application Server 9.0.4.3 and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to Oracle Containers for J2EE, aka OC4J02.
nvd
CVE-2007-0281MEDIUMCVSS 5.0v9.0.4.2v10.1.22007-01-17
CVE-2007-0281 [MEDIUM] CVE-2007-0281: Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04.
nvd
CVE-2007-0287LOWCVSS 1.7v9.0.4.2v10.1.22007-01-17
CVE-2007-0287 [LOW] CVE-2007-0287: Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Coll Unspecified vulnerability in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.2; and Collaboration Suite 9.0.4.2 and 10.1.2; has unknown impact and attack vectors related to Containers for J2EE, aka OC4J08.
nvd
CVE-2007-0282LOWCVSS 3.2v9.0.4.22007-01-17
CVE-2007-0282 [LOW] CVE-2007-0282: Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, Unspecified vulnerability in Oracle HTTP Server 9.0.1.5, Application Server 9.0.4.2 and 10.1.2.0.0, and Collaboration Suite 9.0.4.2 has unknown impact and attack vectors related to the Oracle Process Mgmt & Notification component, aka OPMN02.
nvd
CVE-2007-0286LOWCVSS 2.6v10.1.22007-01-17
CVE-2007-0286 [LOW] CVE-2007-0286: Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Su Unspecified vulnerability in Oracle Application Server 10.1.2.0.2 and 10.1.3.0, and Collaboration Suite 10.1.2, has unknown impact and attack vectors related to Containers for J2EE, aka OC4J07.
nvd
CVE-2007-0275LOWCVSS 3.5PoCv10.1.22007-01-17
CVE-2007-0275 [LOW] CWE-79 CVE-2007-0275: Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow C Cross-site scripting (XSS) vulnerability in Oracle Reports Web Cartridge (RWCGI60) in the Workflow Cartridge component, as used in Oracle Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.2; Collaboration Suite 10.1.2; and Oracle E-Business Suite and Applications 11.5.10CU2; allows remote authenticated users to i
nvd
CVE-2006-5348CRITICALCVSS 10.0v9.0.4.22006-10-18
CVE-2006-5348 [CRITICAL] CVE-2006-5348: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Ora Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, Oracle Collaboration Suite 9.0.4.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS05.
nvd
CVE-2006-5355CRITICALCVSS 10.0v9.0.4.2v10.1.22006-10-18
CVE-2006-5355 [CRITICAL] CVE-2006-5355: Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 1 Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.1.0, Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# SSO01.
nvd
CVE-2006-5354CRITICALCVSS 10.0v9.0.4.2v10.1.22006-10-18
CVE-2006-5354 [CRITICAL] CVE-2006-5354: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10 Unspecified vulnerability in Oracle HTTP Server 9.2.0.7 and 10.1.0.5, Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0, racle Collaboration Suite 9.0.4.2 and 10.1.2, and Oracle E-Business Suite and Applications 11.5.10CU2 has unknown impact and remote attack vectors, aka Vuln# OHS06.
nvd
CVE-2006-5353CRITICALCVSS 10.0v9.0.4.2v10.1.2.02006-10-18
CVE-2006-5353 [CRITICAL] CVE-2006-5353: Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1 Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors related to the Mod_rewrite Module, aka Vuln# OHS01.
nvd
CVE-2006-5356CRITICALCVSS 10.0v9.0.4.2v10.1.2.02006-10-18
CVE-2006-5356 [CRITICAL] CVE-2006-5356: Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4 Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4.3, 10.1.2.0.2, and 10.1.2.1.0, and Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J02.
nvd
CVE-2006-5361CRITICALCVSS 10.0v9.0.4.2v10.1.2.02006-10-18
CVE-2006-5361 [CRITICAL] CVE-2006-5361: Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2 Unspecified vulnerability in Oracle Containers for J2EE in Oracle Application Server 9.0.4.3, 10.1.2.0.0, and 10.1.2.0.1, and Oracle Collaboration Suite 9.0.4.2 and 10.1.2, has unknown impact and remote attack vectors, aka Vuln# OC4J03.
nvd