Vulnerabilities > Oracle > Application Server > 1.0.2.2

DATE CVE VULNERABILITY TITLE RISK
2005-11-02 CVE-2005-3445 Multiple vulnerability in Oracle Application Server and Database Server
Multiple unspecified vulnerabilities in HTTP Server in Oracle Database Server 8i up to 10.1.0.4.2 and Application Server 1.0.2.2 up to 10.1.2.0 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB30 and AS03 or (2) DB31 and AS05.
network
low complexity
oracle
critical
10.0
2004-12-31 CVE-2004-2244 Denial Of Service vulnerability in Oracle Application Server and Oracle9I
The XML parser in Oracle 9i Application Server Release 2 9.0.3.0 and 9.0.3.1, 9.0.2.3 and earlier, and Release 1 1.0.2.2 and 1.0.2.2.2, and Database Server Release 2 9.2.0.1 and later, allows remote attackers to cause a denial of service (CPU and memory consumption) via a SOAP message containing a crafted DTD.
network
low complexity
oracle
5.0
2004-07-30 CVE-2004-1707 Privilege Escalation vulnerability in Oracle Database Default Library Directory
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default path to find and execute library files while operating at raised privileges, which allows certain Oracle user accounts to gain root privileges via a modified libclntsh.so.9.0.
local
low complexity
oracle
7.2
2004-03-30 CVE-2004-1877 Authentication Credential Disclosure vulnerability in Oracle Application Server and Http Server
The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.
network
high complexity
oracle
2.6
2002-12-31 CVE-2002-2347 Cross-Site Scripting vulnerability in Oracle Application Server
Cross-site scripting (XSS) vulnerability in Oracle Java Server Page (OJSP) demo files (1) hellouser.jsp, (2) welcomeuser.jsp and (3) usebean.jsp in Oracle 9i Application Server 9.0.2, 1.0.2.2, 1.0.2.1s and 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the text entry field.
network
oracle CWE-79
4.3
2002-12-31 CVE-2002-1858 Unspecified vulnerability in Oracle Application Server
Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a trailing dot ("WEB-INF.").
network
low complexity
oracle
5.0
2002-12-31 CVE-2002-1632 Information Disclosure vulnerability in Oracle 9i Application Server Sample Scripts
Oracle 9i Application Server (9iAS) installs multiple sample pages that allow remote attackers to obtain environment variables and other sensitive information via (1) info.jsp, (2) printenv, (3) echo, or (4) echo2.
network
low complexity
oracle
6.4
2002-12-31 CVE-2002-1631 Information Disclosure vulnerability in Oracle 9i Application Server Sample Scripts
SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.
network
low complexity
oracle
7.5
2002-12-31 CVE-2002-1630 Information Disclosure vulnerability in Oracle 9i Application Server Sample Scripts
The sendmail.jsp sample page in Oracle 9i Application Server (9iAS) allows remote attackers to send arbitrary emails.
network
low complexity
oracle
7.5
2002-08-12 CVE-2002-0659 Denial Of Service vulnerability in OpenSSL ASN.1 Parsing Error
The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings.
network
low complexity
openssl oracle apple
5.0