Vulnerabilities > Oracle > Application Server Portal > 9.0.2.3a

DATE CVE VULNERABILITY TITLE RISK
2004-07-30 CVE-2004-1707 Privilege Escalation vulnerability in Oracle Database Default Library Directory
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
local
low complexity
oracle
7.2
2003-11-03 CVE-2003-1193 SQL Injection vulnerability in Oracle9iAS Portal Component
Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.
network
low complexity
oracle
7.5