Vulnerability Note VU#435974
Oracle Application Server contains several vulnerabilities
Overview
Several vulnerabilities exist in the Portal and iSQL*Plus components of the Oracle Application Server. According the the Oracle Security Alert, exploitation of these vulnerabilities would require the attacker to have network access, but not a valid user account on the vulnerable system.
Description
Oracle Application Server 10g (9.0.4) versions 9.0.4.0 and 9.0.4.1, Oracle9i Application Server Release 2 versions 9.0.2.3 and 9.0.3.1 and Oracle9i Application Server Release 1 version 1.0.2.2 contain multiple vulnerabilities in the in the Portal and iSQL*Plus components. In order to exploit these vulnerabilities an attacker would need to have network access to the vulnerable systems. |
Impact
The complete impact of this vulnerabilities is not clear. Oracle has rated this issue as High. For more information about Oracle's severity ratings please see: |
Solution
Apply the appropriate patch or upgrade as specified in the Oracle Security Alert #68 (pdf).
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Oracle Corporation | Affected | - | 01 Sep 2004 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.oracle.com/technology/deploy/security/alerts.htm
- http://www.securitytracker.com/alerts/2004/Aug/1011110.html
- http://secunia.com/advisories/12409/
- http://www.oracle.com/technology/deploy/security/alerts.htm
- http://www.securitytracker.com/alerts/2004/Sep/1011126.html
Credit
These vulnerabilities were discovered by several parties and reported in an Oracle Security Alert.
This document was written by Jason A Rafail.
Other Information
- CVE IDs: Unknown
- Date Public: 31 Aug 2004
- Date First Published: 01 Sep 2004
- Date Last Updated: 01 Sep 2004
- Severity Metric: 27.42
- Document Revision: 9
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.