Vulnerability Name: CVE-2006-5351 (CCN-30108) Assigned: 2006-10-17 Published: 2006-10-17 Updated: 2018-10-17 Summary: Multiple unspecified vulnerabilities in Oracle Application Express (formerly Oracle HTML DB) 1.5 up to 2.0 have unknown impact and remote attack vectors, aka Vuln# (1) APEX01, (2) APEX02, (3) APEX03, (4) APEX05, (5) APEX06, (6) APEX07, (7) APEX08, (8) APEX09, (9) APEX10, (10) APEX11, (11) APEX12, (12) APEX13, (13) APEX14, (14) APEX15, (15) APEX16, (16) APEX17, (17) APEX18, (18) APEX19, (19) APEX22, (20) APEX23, (21) APEX24, (22) APEX25, (23) APEX26, (24) APEX27, (25) APEX28, (26) APEX29, (27) APEX30, (28) APEX31, (29) APEX32, (30) APEX33, (31) APEX34, and (32) APEX35. Note : as of 20061027, it is likely that some of these identifiers are associated with cross-site scripting (XSS) in WWV_FLOW_ITEM_HELP and NOTIFICATION_MSG, but these have been provided separate identifiers. CVSS v3 Severity: 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): NoneAvailibility (A): None
CVSS v2 Severity: 9.0 High (CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C )7.9 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N )2.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N/E:H/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): NoneAvailibility (A): None
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Informational References: Source: CCN Type: Full-Disclosure Mailing List, Mon Oct 23 2006 - 11:43:57 CDTCross-Site-Scripting Vulnerability in Oracle APEX WWV_FLOW_ITEM_HELP Source: MITRE Type: CNACVE-2006-5351 Source: CCN Type: SA22396Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory22396 Source: CCN Type: SECTRACK ID: 1017077Oracle Database and Other Products Have Multiple Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: UNKNOWN1017077 Source: CCN Type: Oracle Critical Patch Update - October 2006Oracle Critical Patch Update Advisory - October 2006 Source: CONFIRM Type: UNKNOWNhttp://www.oracle.com/technetwork/topics/security/cpuoct2006-095368.html Source: CCN Type: Red-Database-Security Web siteDetails Oracle Critical Patch Update October 2006 - V1.02 Source: MISC Type: UNKNOWNhttp://www.red-database-security.com/advisory/oracle_cpu_oct_2006.html Source: HP Type: UNKNOWNHPSBMA02133 Source: BID Type: Patch20588 Source: CCN Type: BID-20588Oracle October 2006 Security Update Multiple Vulnerabilities Source: CERT Type: US Government ResourceTA06-291A Source: VUPEN Type: Vendor AdvisoryADV-2006-4065 Source: XF Type: UNKNOWNoracle-wwv-flow-xss(30108) Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:apex:1.5.0:*:*:*:*:*:*:* OR cpe:/a:oracle:apex:2.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:9.0.4.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.0.1.5:*:fips:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.0:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.0:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:10.1.2:r1:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.8:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_portal:8.9:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:6i:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:* OR cpe:/a:oracle:enterpriseone:8.95:*:*:*:*:*:*:* OR cpe:/a:oracle:enterpriseone:8.96:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.22:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.4.3:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:10.1.2.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:10.1.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:apex:2.0:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.7:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.8:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:* OR cpe:/a:oracle:pharmaceutical:4.5.0:*:*:*:*:*:*:* OR cpe:/a:oracle:pharmaceutical:4.5.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle apex 1.5.0
oracle apex 2.0
oracle application server 1.0.2.2
oracle database server 8.1.7.4
oracle database server 9.2.0.6 r2
oracle database server 10.1.0.3 r1
oracle application server 9.0.4.1
oracle collaboration suite 9.0.4.2 r2
oracle database server 9.0.1.5
oracle database server 10.1.0.4 r1
oracle e-business suite 11.0
oracle developer suite 9.0.4.1
oracle application server 9.0.4.2
oracle application server 10.1.2.0.0 r2
oracle application server 10.1.2.0.1 r2
oracle application server 10.1.2.0.2 r2
oracle database server 10.2.0.1 r2
oracle database server 10.1.0.5 r1
oracle database server 9.2.0.7 r2
oracle collaboration suite 10.1.2 r1
oracle e-business suite 11.5.10
oracle peoplesoft enterprise portal 8.8
oracle peoplesoft enterprise portal 8.9
oracle developer suite 6i
oracle developer suite 9.0.4.2
oracle database server 10.2.0.2 r2
oracle application server 9.0.4.3
oracle enterpriseone 8.95
oracle enterpriseone 8.96
oracle peoplesoft enterprise peopletools 8.22
oracle peoplesoft enterprise peopletools 8.47
oracle peoplesoft enterprise peopletools 8.48
oracle developer suite 9.0.4.3
oracle developer suite 10.1.2.0.2
oracle developer suite 10.1.2.2
oracle apex 2.0
oracle e-business suite 11.5.7
oracle e-business suite 11.5.8
oracle e-business suite 11.5.9
oracle pharmaceutical 4.5.0
oracle pharmaceutical 4.5.1