VYPR

Oracle9i Application Server

by Oracle Corporation

CVEs (23)

  • CVE-2003-1193Nov 3, 2003
    risk 0.00cvss epss 0.02

    Multiple SQL injection vulnerabilities in the Portal DB (1) List of Values (LOVs), (2) Forms, (3) Hierarchy, and (4) XML components packages in Oracle Oracle9i Application Server 9.0.2.00 through 3.0.9.8.5 allow remote attackers to execute arbitrary SQL commands via the URL.

  • CVE-2002-1858Dec 31, 2002
    risk 0.00cvss epss 0.05

    Oracle Oracle9i Application Server 1.0.2.2 and 9.0.2 through 9.0.2.0.1, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configuration information, via a request to the WEB-INF directory with a…

  • CVE-2001-0326May 3, 2001
    risk 0.00cvss epss 0.05

    Oracle Java Virtual Machine (JVM ) for Oracle 8.1.7 and Oracle Application Server 9iAS Release 1.0.2.0.1 allows remote attackers to read arbitrary files via the .jsp and .sqljsp file extensions when the server is configured to use the <> FilePermission.

Page 2 of 2