Oracle Collaboration Suite vulnerabilities
62 known vulnerabilities affecting oracle/collaboration_suite.
Total CVEs
62
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL28HIGH17MEDIUM11LOW6
Vulnerabilities
Page 3 of 4
CVE-2006-5346HIGHCVSS 7.6v9.0.4.22006-10-18
CVE-2006-5346 [HIGH] CVE-2006-5346: Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4
Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, as used in Oracle Collaboration Suite 9.0.4.2 and Oracle E-Business Suite and Applications 11.5.10CU2, has unknown impact and remote attack vectors related to htdigest, aka Vuln# OHS02.
nvd
CVE-2006-5363LOWCVSS 2.6v10.1.2.02006-10-18
CVE-2006-5363 [LOW] CVE-2006-5363: Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 10.1.2.0.1
Unspecified vulnerability in Oracle Single Sign-On component in Oracle Application Server 10.1.2.0.1 and Collaboration Suite 10.1.2 has unknown impact and remote attack vectors, aka Vuln# SSO02.
nvd
CVE-2006-5364LOWCVSS 2.1v10.1.2.02006-10-18
CVE-2006-5364 [LOW] CVE-2006-5364: Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4
Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 9.0.4.1 and 10.1.2.0.2, and Collaboration Suite 10.1.2, has unknown impact and remote authenticated attack vectors, aka Vuln# OC4J05.
nvd
CVE-2006-3715CRITICALCVSS 10.0v10.1.22006-07-21
CVE-2006-3715 [CRITICAL] CVE-2006-3715: Unspecified vulnerability in Calendar for Oracle Collaboration Suite 10.1.2 has unknown impact and a
Unspecified vulnerability in Calendar for Oracle Collaboration Suite 10.1.2 has unknown impact and attack vectors, aka Oracle Vuln# OCS01.
nvd
CVE-2006-1879CRITICALCVSS 10.0v9.0.4.2v10.1.1+2 more2006-04-20
CVE-2006-1879 [CRITICAL] CVE-2006-1879: Multiple unspecified vulnerabilities in the Email Server component in Oracle Collaboration Suite 9.0
Multiple unspecified vulnerabilities in the Email Server component in Oracle Collaboration Suite 9.0.4.2, 10.1.1, 10.1.2.0, and 10.1.2.1 have unknown impact and attack vectors, aka Vuln# (1) OCS01, (2) OCS02, (3) OCS03, and (4) OCS04.
nvd
CVE-2006-1884CRITICALCVSS 10.0v9.0.4.22006-04-20
CVE-2006-1884 [CRITICAL] CVE-2006-1884: Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business S
Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01.
nvd
CVE-2006-0552HIGHCVSS 7.5v9.0.4.2v10.1.1+2 more2006-02-04
CVE-2006-0552 [HIGH] CVE-2006-0552: Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5,
Unspecified vulnerability in the Net Listener component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, and 9.2.0.7 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB11.
nvd
CVE-2006-0276CRITICALCVSS 10.0v9.0.4.22006-01-18
CVE-2006-0276 [CRITICAL] CVE-2006-0276: Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracl
Multiple unspecified vulnerabilities in Oracle Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, 2) OCS02, 3) OCS03, 4) OCS04, 5) OCS05, 6) OCS06, 7) OCS07, (8) OCS08, and (9) OCS09 in the (a) Email Server component; 10) OCS10 (and (11) OCS11 in the (b) Oracle Colla
nvd
CVE-2006-0283CRITICALCVSS 10.0v9.0.4.22006-01-18
CVE-2006-0283 [CRITICAL] CVE-2006-0283: Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and C
Unspecified vulnerability in Oracle Database Server 10.1.0.4.2, Application Server 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC02 in the Reorganize Objects & Convert Tablespace component.
nvd
CVE-2006-0291CRITICALCVSS 10.0v9.0.4.22006-01-18
CVE-2006-0291 [CRITICAL] CVE-2006-0291: Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2
Multiple unspecified vulnerabilities in Oracle Database Server 10.2.0.1, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 have unspecified impact and attack vectors, as identified by Oracle Vuln# (1) WF02 and (2) WF03 in the Oracle Workflow Cartridge component.
nvd
CVE-2006-0282CRITICALCVSS 10.0v9.0.4.22006-01-18
CVE-2006-0282 [CRITICAL] CVE-2006-0282: Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.
Unspecified vulnerability in Oracle Database Server 8.1.7.4, 9.0.1.5, 9.0.1.5 FIPS, 9.2.0.7, and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, and 10.1.2.0.2, and Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i) has unspecified impact and attack vectors, as identified by Oracle Vuln# DBC01 in the Protocol Support component.
nvd
CVE-2006-0290CRITICALCVSS 10.0v9.0.4.22006-01-18
CVE-2006-0290 [CRITICAL] CVE-2006-0290: Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1
Unspecified vulnerability in Oracle Database Server 9.2.0.7, Application Server 9.0.4.2 and 10.1.2.1, Collaboration Suite Release 2, version 9.0.4.2 (Oracle9i), and E-Business Suite and Applications 11.5.10 has unspecified impact and attack vectors, as identified by Oracle Vuln# WF01 in the Oracle Workflow Cartridge component.
nvd
CVE-2005-3454CRITICALCVSS 10.0v9.0.4.2v10.1.12005-11-02
CVE-2005-3454 [CRITICAL] CVE-2005-3454: Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10g Release 1 version 10.1.1 and
Multiple unspecified vulnerabilities in Oracle Collaboration Suite 10g Release 1 version 10.1.1 and 9i Release 2 9.0.4.2 have unknown impact and attack vectors, as identified by Oracle Vuln# (1) OCS01, (2) OCS02, (3) OCS03, and (4) OCS04 for Calendar; (5) OCS05, (6) OCS06, (7) OCS07, (8) OCS08, (9) OCS09, and (10) OCS10 for Email Server; and (11) OCS11, (12)
nvd
CVE-2004-1371CRITICALCVSS 9.0vrelease_12004-08-04
CVE-2004-1371 [CRITICAL] CWE-119 CVE-2004-1371: Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code v
Stack-based buffer overflow in Oracle 9i and 10g allows remote attackers to execute arbitrary code via a long token in the text of a wrapped procedure.
nvd
CVE-2004-1362HIGHCVSS 7.5vrelease_12004-08-04
CVE-2004-1362 [HIGH] CVE-2004-1362: The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
nvd
CVE-2004-1370HIGHCVSS 7.5vrelease_12004-08-04
CVE-2004-1370 [HIGH] CVE-2004-1370: Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9
Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION, (2) WK_ACL.GET_ACL, (3) WK_ACL.STORE_ACL, (4) WK_ADM.COMPLETE_ACL_SNAPSHOT, (5) WK_ACL.DELETE_ACLS_WITH_STATEMENT, or (6) DRILOAD.VALIDATE_STMT.
nvd
CVE-2004-1368HIGHCVSS 7.8vrelease_12004-08-04
CVE-2004-1368 [HIGH] CVE-2004-1368: ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an
ISQL*Plus in Oracle 10g Application Server allows remote attackers to execute arbitrary files via an absolute pathname in the file parameter to the load.uix script.
nvd
CVE-2004-1364HIGHCVSS 8.5PoCvrelease_12004-08-04
CVE-2004-1364 [HIGH] CWE-22 CVE-2004-1364: Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
nvd
CVE-2004-1365MEDIUMCVSS 4.6vrelease_12004-08-04
CVE-2004-1365 [MEDIUM] CVE-2004-1365: Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function
Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user.
nvd
CVE-2004-1367MEDIUMCVSS 4.4vrelease_12004-08-04
CVE-2004-1367 [MEDIUM] CWE-200 CVE-2004-1367: Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!")
Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable postDBCreation.log file, which could allow local users to obtain that password and use it against SYS or SYSTEM accounts, which may have been installed
nvd