← Back

Application Server

application_server

Vendor: Oracle • 198 CVEs

CVEs (198)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
10Broadcom
DebianFedoraproject+7 more
26Active Iq Unified Manager
Application ServerDebian Linux+23 more
Nov 21, 2024
Apr 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert"...Show more
Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from the peer. This could be exploited by a malicious peer in a Denial of Service attack. OpenSSL version 1.1.1d, 1.1.1e, and 1.1.1f are affected by this issue. This issue did not affect OpenSSL versions prior to 1.1.1d. Fixed in OpenSSL 1.1.1g (Affected 1.1.1d-1.1.1f).Show less
7Canonical
DebianNodejs+4 more
20Api Gateway
Application ServerDebian Linux+17 more
Nov 21, 2024
Nov 15, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
6Canonical
DebianNetapp+3 more
22Api Gateway
Application ServerCloud Backup+19 more
Nov 21, 2024
Oct 29, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affect...Show more
The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1).Show less
1Oracle
1Application Server
Apr 23, 2026
Jan 13, 2010
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect integrity via unknown vectors.
1Oracle
1Application Server
Apr 23, 2026
Jan 13, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Oracle Containers for J2EE component in Oracle Application Server 10.1.2.3 and 10.1.3.4 allows remote attackers to affect confidentiality via unknown vectors.
1Oracle
1Application Server
Apr 23, 2026
Jan 13, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in the Access Manager Identity Server component in Oracle Application Server 7.0.4.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors.
1Oracle
2Application Server
Database Server
Apr 23, 2026
Jan 13, 2010
N/A· v4
N/A· v3
1.0 LOW· v2
Unspecified vulnerability in the Unzip component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5; and Oracle Application Server 10.1.2.3; allows local users to affect confidentiality via unknown vectors.
1Oracle
1Application Server
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2...Show more
Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-0983.Show less
1Oracle
1Application Server
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Business Intelligence Enterprise Edition component in unspecified Oracle Application Server versions allows remote attackers to affect integrity via unknown vectors.
1Oracle
1Application Server
Apr 23, 2026
Oct 22, 2009
N/A· v4
N/A· v3
1.7 LOW· v2
Unspecified vulnerability in the Business Intelligence Enterprise Edition component in Oracle Application Server 10.1.3.4.1 allows local users to affect confidentiality via unknown vectors.
1Oracle
1Application Server
Apr 23, 2026
Sep 14, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3 and 10.1.2.2 allows remote authenticated users to affect confidentiality via unknown vectors, aka AS06.
1Oracle
1Application Server
Apr 23, 2026
Sep 14, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 and 10.1.3.1 allows remote attackers to affect integrity via unknown vectors, aka AS05.
1Oracle
2Application Server
E Business Suite
Apr 23, 2026
Sep 14, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the Oracle Forms component in Oracle Application Server 10.1.2.2 and E-Business Suite 12.0.3 allows remote attackers to affect integrity via unknown vectors, aka AS04.
1Oracle
1Application Server
Apr 23, 2026
Sep 14, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Unspecified vulnerability in the Oracle BPEL Worklist Application component in Oracle Application Server 10.1.2.2 and 10.1.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown ve...Show more
Unspecified vulnerability in the Oracle BPEL Worklist Application component in Oracle Application Server 10.1.2.2 and 10.1.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, aka AS03.Show less
1Oracle
2Application Server
E Business Suite 11i
Apr 23, 2026
Sep 14, 2009
N/A· v4
N/A· v3
9.3 HIGH· v2
Unspecified vulnerability in the E-Business Application client, as used in Oracle Application Server 1.1.8.26 and E-Business Suite 11.5.10.2, allows remote attackers to affect confidentiality, integrity, and availability...Show more
Unspecified vulnerability in the E-Business Application client, as used in Oracle Application Server 1.1.8.26 and E-Business Suite 11.5.10.2, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Oracle Jinitiator component, aka AS02.Show less
1Oracle
1Application Server
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.
3Ibm
Mono ProjectOracle
5Application Server
Bea Product SuiteMono+2 more
Apr 23, 2026
Jul 14, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4,...Show more
The design of the W3C XML Signature Syntax and Processing (XMLDsig) recommendation, as implemented in products including (1) the Oracle Security Developer Tools component in Oracle Application Server 10.1.2.3, 10.1.3.4, and 10.1.4.3IM; (2) the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, and 8.1 SP6; (3) Mono before 2.4.2.2; (4) XML Security Library before 1.2.12; (5) IBM WebSphere Application Server Versions 6.0 through 6.0.2.33, 6.1 through 6.1.0.23, and 7.0 through 7.0.0.1; (6) Sun JDK and JRE Update 14 and earlier; (7) Microsoft .NET Framework 3.0 through 3.0 SP2, 3.5, and 4.0; and other products uses a parameter that defines an HMAC truncation length (HMACOutputLength) but does not require a minimum for this length, which allows attackers to spoof HMAC-based signatures and bypass authentication by specifying a truncation length with a small number of bits.Show less
1Oracle
1Application Server
Apr 23, 2026
Apr 15, 2009
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a differen...Show more
Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-0994.Show less
1Oracle
1Application Server
Apr 23, 2026
Apr 15, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previou...Show more
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is for multiple integer overflows in a function that parses an optional data stream within a Microsoft Office file, leading to a heap-based buffer overflow.Show less
2Ibm
Oracle
2Application Server
Websphere Portal
Apr 23, 2026
Apr 15, 2009
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulner...Show more
Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1008.Show less