Vulnerabilities > Oracle > Application Server > 1.0.2.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2005-11-02 | CVE-2005-3445 | Multiple vulnerability in Oracle Application Server and Database Server Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05. | 10.0 |
2004-12-31 | CVE-2004-2244 | Denial Of Service vulnerability in Oracle Application Server and Oracle9I The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD. | 5.0 |
2004-07-30 | CVE-2004-1707 | Privilege Escalation vulnerability in Oracle Database Default Library Directory The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0. | 7.2 |
2004-03-30 | CVE-2004-1877 | Authentication Credential Disclosure vulnerability in Oracle Application Server and Http Server The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password. | 2.6 |
2002-12-31 | CVE-2002-2347 | Cross-Site Scripting vulnerability in Oracle Application Server Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field. | 4.3 |
2002-12-31 | CVE-2002-1858 | Unspecified vulnerability in Oracle Application Server Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF."). | 5.0 |
2002-12-31 | CVE-2002-1632 | Information Disclosure vulnerability in Oracle 9i Application Server Sample Scripts Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2. | 6.4 |
2002-12-31 | CVE-2002-1631 | Information Disclosure vulnerability in Oracle 9i Application Server Sample Scripts SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter. | 7.5 |
2002-12-31 | CVE-2002-1630 | Information Disclosure vulnerability in Oracle 9i Application Server Sample Scripts The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails. | 7.5 |
2002-08-12 | CVE-2002-0659 | Denial Of Service vulnerability in OpenSSL ASN.1 Parsing Error The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings. | 5.0 |