Skip to main content

Vendor/product archive

sun / java_system_application_server CVEs

Beta · best-effort

22 CVEs tagged to sun / java_system_application_server2 Critical, 3 High, 16 Medium, 1 Low, 0 Unrated.

CVE-2010-0386

Published Jan 25, 2010

The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authe…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0278

Published Jan 27, 2009

Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malf…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4511

Published Aug 23, 2007

The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualAuth ORB listener ser…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4025

Published Jul 26, 2007

Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4804

Published Dec 31, 2005

Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote attackers to read .jar…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4805

Published Dec 31, 2005

Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update 2 and earlier, allow…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0742

Published May 2, 2005

Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0826

Published Dec 31, 2004

Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 cli…

CVSS 7.5 · High
Showing 1-22 of 22 CVEsPage 1 of 1