← Back

CVE-2004-1877

nvd nist
Published: Mar 30, 2004Modified: Apr 16, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

The p_submit_url value in the sample login form in the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2(9.0.2) for Oracle SSO allows remote attackers to spoof the login page, which could allow users to inadvertently reveal their username and password.

Affected (15)

2 products
Application Server
Http Server
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.0.2.1s
Version 1.0.2.2.2
Version 1.0.2.2
Version 1.0.2
Version 9.0.2.0.0
Version 9.0.2.0.1
Version 9.0.2.1
Version 9.0.2.2
Version 9.0.2.3
Version 9.0.2
Version 9.0.3.1
Version 9.0.3
Oracle
Version 8.1.7
Version 9.0.1
Version 9.2.0

References (6)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.