Vulnerabilities > Oracle > Application Server > 1.0.2.2.2

DATE CVE VULNERABILITY TITLE RISK
2009-01-14 CVE-2008-4014 Multiple vulnerability in Oracle January 2009 Critical Patch Update
Unspecified vulnerability in the Oracle BPEL Process Manager component in Oracle Application Server allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
network
low complexity
oracle
5.5
2006-01-26 CVE-2006-0435 Unspecified vulnerability in Oracle Application Server and Http Server
Unspecified vulnerability in Oracle PL/SQL (PLSQL), as used in Database Server DS 9.2.0.7 and 10.1.0.5, Application Server 1.0.2.2, 9.0.4.2, 10.1.2.0.2, 10.1.2.1.0, and 10.1.3.0.0, E-Business Suite and Applications 11.5.10, and Collaboration Suite 10.1.1, 10.1.2.0, 10.1.2.1, and 9.0.4.2, allows attackers to bypass the PLSQLExclusion list and access excluded packages and procedures, aka Vuln# PLSQL01.
network
low complexity
oracle
7.5
2004-12-31 CVE-2004-2244 Denial Of Service vulnerability in Oracle Application Server and Oracle9I
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
network
low complexity
oracle
5.0
2004-07-30 CVE-2004-1707 Privilege Escalation vulnerability in Oracle Database Default Library Directory
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
local
low complexity
oracle
7.2
2004-03-30 CVE-2004-1877 Authentication Credential Disclosure vulnerability in Oracle Application Server and Http Server
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
network
high complexity
oracle
2.6
2000-12-31 CVE-2000-1236 Unspecified vulnerability in Oracle Application Server
SQL injection vulnerability in mod_sql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the query string of the URL.
network
low complexity
oracle
7.5
2000-12-31 CVE-2000-1235 Unspecified vulnerability in Oracle Application Server
The default configurations of (1) the port listener and (2) modplsql in Oracle Internet Application Server (IAS) 3.0.7 and earlier allow remote attackers to view privileged database information via HTTP requests for Database Access Descriptor (DAD) files.
network
low complexity
oracle
5.0