Skip to main content

Vendor/product archive

oracle / application_server_portal CVEs

Beta · best-effort

6 CVEs tagged to oracle / application_server_portal0 Critical, 3 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2008-2138

Published May 12, 2008

Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request co…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1506

Published Mar 19, 2007

Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote attackers to inject arbitrary web script or HTML via the (…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6699

Published Dec 23, 2006

Multiple CRLF injection vulnerabilities in Oracle Portal 9.0.2 and possibly other versions allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitt…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6697

Published Dec 22, 2006

CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTT…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1193

Published Nov 3, 2003

Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1