Vulnerability Name: CVE-2007-0281 (CCN-31541) Assigned: 2007-01-16 Published: 2007-01-16 Updated: 2017-07-29 Summary: Multiple unspecified vulnerabilities in Oracle HTTP Server 9.0.1.5, 9.2.0.8, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3, 10.1.2.0.0, 10.1.2.0.1, 10.1.2.0.2, 10.1.2.1, and 10.1.3.0; and Collaboration Suite 9.0.4.2 and 10.1.2; have unknown impact and attack vectors related to the Oracle HTTP Server, aka (1) OHS03 and (2) OHS04. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): LowAvailibility (A): None
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): PartialAvailibility (A): None
Vulnerability Type: CWE-Other Vulnerability Consequences: Informational References: Source: MITRE Type: CNACVE-2007-0268 Source: MITRE Type: CNACVE-2007-0269 Source: MITRE Type: CNACVE-2007-0270 Source: MITRE Type: CNACVE-2007-0271 Source: MITRE Type: CNACVE-2007-0272 Source: MITRE Type: CNACVE-2007-0273 Source: MITRE Type: CNACVE-2007-0274 Source: MITRE Type: CNACVE-2007-0275 Source: MITRE Type: CNACVE-2007-0276 Source: MITRE Type: CNACVE-2007-0277 Source: MITRE Type: CNACVE-2007-0278 Source: MITRE Type: CNACVE-2007-0279 Source: MITRE Type: CNACVE-2007-0280 Source: MITRE Type: CNACVE-2007-0281 Source: MITRE Type: CNACVE-2007-0282 Source: MITRE Type: CNACVE-2007-0283 Source: MITRE Type: CNACVE-2007-0284 Source: MITRE Type: CNACVE-2007-0285 Source: MITRE Type: CNACVE-2007-0286 Source: MITRE Type: CNACVE-2007-0287 Source: MITRE Type: CNACVE-2007-0288 Source: MITRE Type: CNACVE-2007-0289 Source: MITRE Type: CNACVE-2007-0290 Source: MITRE Type: CNACVE-2007-0291 Source: MITRE Type: CNACVE-2007-0292 Source: MITRE Type: CNACVE-2007-0293 Source: MITRE Type: CNACVE-2007-0294 Source: MITRE Type: CNACVE-2007-0295 Source: MITRE Type: CNACVE-2007-0296 Source: MITRE Type: CNACVE-2007-0297 Source: OSVDB Type: UNKNOWN32883 Source: OSVDB Type: UNKNOWN32884 Source: CCN Type: SA23794Oracle Products Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory23794 Source: CCN Type: SECTRACK ID: 1017522Oracle Database and Other Products Have 52 Unspecified Vulnerabilities With Unspecified Impact Source: SECTRACK Type: UNKNOWN1017522 Source: CCN Type: US-CERT VU#221788Oracle SYS.DBMS_AQ package vulnerable to PL/SQL injection Source: CCN Type: Oracle Critical Patch Update - January 2007Oracle Critical Patch Update Advisory - January 2007 Source: CONFIRM Type: UNKNOWNhttp://www.oracle.com/technetwork/topics/security/cpujan2007-101493.html Source: CCN Type: OSVDB ID: 32872Oracle PeopleSoft PeopleTools PIA Component HTTP Unspecified Remote DoS Source: CCN Type: OSVDB ID: 32873Oracle PeopleSoft PeopleTools PIA Component HTTP Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32874Oracle PeopleSoft PeopleTools HTTP Unspecified Authenticated XSS Source: CCN Type: OSVDB ID: 32880Oracle Enterprise Manager Cloning & Data Guard Management Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32881Oracle HTTP Server SSL Module Unspecified Remote Issue (OHS01) Source: CCN Type: OSVDB ID: 32882Oracle HTTP Server SSL Module Unspecified Remote Issue (OHS02) Source: CCN Type: OSVDB ID: 32883Oracle HTTP Server Unspecified Issue (OHS03) Source: CCN Type: OSVDB ID: 32884Oracle HTTP Server Unspecified Issue (OHS04) Source: CCN Type: OSVDB ID: 32885Oracle HTTP Server SSL Module Unspecified Remote DoS (OHS05) Source: CCN Type: OSVDB ID: 32886Oracle HTTP Server SSL Module Unspecified Remote DoS (OHS06) Source: CCN Type: OSVDB ID: 32887Oracle HTTP Server Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32888Oracle E-Business Suite Application Object Library HTTP Authenticated Unspecified Issue Source: CCN Type: OSVDB ID: 32889Oracle E-Business Suite Exchange HTTP Negotiations User Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32890Oracle E-Business Suite Human Resources Administrator Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32891Oracle E-Business Suite Payables User Account Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32892Oracle E-Business Suite Trading Community Architecture Administrator Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32893Oracle E-Business Suite Web Applications Desktop Integrator Unspecified Issue Source: CCN Type: OSVDB ID: 32894Oracle Multiple Products Reports Developer HTTP Unspecified Issue Source: CCN Type: OSVDB ID: 32895Oracle Multiple Products Containers for J2EE HTTP Unspecified Issue (OC4J01) Source: CCN Type: OSVDB ID: 32896Oracle Multiple Products Containers for J2EE HTTP Unspecified Issue (OC4J02) Source: CCN Type: OSVDB ID: 32897Oracle Multiple Products Containers for J2EE HTTP Unspecified Information Disclosure (OC4J03) Source: CCN Type: OSVDB ID: 32898Oracle Multiple Products Containers for J2EE HTTP Unspecified Issue (OC4J04) Source: CCN Type: OSVDB ID: 32899Oracle Collaboration Suite Containers for J2EE HTTP Unspecified Information Disclosure (OC4J05) Source: CCN Type: OSVDB ID: 32900Oracle Collaboration Suite Containers for J2EE HTTP Unspecified Issue (OC4J06) Source: CCN Type: OSVDB ID: 32901Oracle Multiple Products Containers for J2EE Unauthenticated Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32902Oracle Multiple Products Containers for J2EE jazn.jar Local Information Disclosure Source: CCN Type: OSVDB ID: 32903Oracle Application Server Internet Directory LDAP Unspecified Information Disclosure Source: CCN Type: OSVDB ID: 32904Oracle Multiple Products Process Mgmt & Notification ONS OPMN Daemon Remote Format String (OPMN02) Source: CCN Type: OSVDB ID: 32906Oracle Multiple Products Workflow Cartridge rwcgi60 genuser Parameter XSS Source: CCN Type: OSVDB ID: 32908Oracle Database Change Data Capture sys.dbms_cdc_subscribe Unspecified Issue Source: CCN Type: OSVDB ID: 32916Oracle Database Advanced Security Option oklist / okdstry Unspecified Local Issue Source: CCN Type: OSVDB ID: 32917Oracle Database Export expdp / impdp Unspecified Local Issue Source: CCN Type: OSVDB ID: 32918Oracle Database NLS Runtime lmsgen Unspecified Local Issue Source: CCN Type: OSVDB ID: 32919Oracle Database Net Services tnslsnr Unspecified Local Issue Source: CCN Type: OSVDB ID: 32920Oracle Database Text ctxkbtc Unspecified Local Issue Source: CCN Type: OSVDB ID: 32922Oracle Database Recovery Manager oklist Unspecified Local Issue Source: CCN Type: Red-Database-Security Web siteDetails Oracle Critical Patch Update January 2007 Source: CCN Type: BID-22008Retired: Oracle January 2007 Advance Notification Multiple Vulnerabilities Source: BID Type: UNKNOWN22083 Source: CCN Type: US-CERT Technical Cyber Security Alert TA07-017AOracle Releases Patches for Multiple Vulnerabilities Source: CERT Type: Patch, US Government ResourceTA07-017A Source: XF Type: UNKNOWNoracle-cpu-jan2007(31541) Source: XF Type: UNKNOWNoracle-cpu-jan2007(31541) Source: CCN Type: IBM Internet Security Systems X-Force DatabaseOracle Application Server EmChartBean directory traversal Vulnerable Configuration: Configuration 1 :cpe:/a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:collaboration_suite:10.1.2:*:*:*:*:*:*:* OR cpe:/a:oracle:http_server:9.0.1.5:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:8.1.7.4:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.6:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.3:r1:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.1:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.0.1.5::fips:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.4:r1:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.0:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.3:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.2:*:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.1.0.4:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.0:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:application_server:10.1.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.1:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.1.0.5:r1:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.7:r2:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.10:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:6i:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.2:r2:*:*:*:*:*:* OR cpe:/a:oracle:enterprise_manager_grid_control:10.2.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:application_server:9.0.4.3:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.22:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.47:*:*:*:*:*:*:* OR cpe:/a:oracle:peoplesoft_enterprise_peopletools:8.48:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:9.0.4.3:*:*:*:*:*:*:* OR cpe:/a:oracle:developer_suite:10.1.2.0.2:*:*:*:*:*:*:* OR cpe:/a:oracle:database_server:9.2.0.8:r2:*:*:*:*:*:* OR cpe:/a:oracle:database_server:10.2.0.3:r2:*:*:*:*:*:* OR cpe:/a:oracle:identity_management_10g:10.1.4.0.1:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.7:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.8:*:*:*:*:*:*:* OR cpe:/a:oracle:e-business_suite:11.5.9:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
oracle application server 9.0.4.3
oracle application server 10.1.2.0.2
oracle application server 10.1.2.2
oracle collaboration suite 9.0.4.2
oracle collaboration suite 10.1.2
oracle http server 9.0.1.5
oracle application server 1.0.2.2
oracle database server 8.1.7.4
oracle database server 9.2.0.6 r2
oracle database server 10.1.0.3 r1
oracle application server 9.0.4.1
oracle database server 9.0.1.5
oracle database server 10.1.0.4 r1
oracle e-business suite 11.0
oracle enterprise manager grid control 10.1.0.3
oracle application server 9.0.4.2
oracle enterprise manager grid control 10.1.0.4
oracle application server 10.1.2.0.0 r2
oracle application server 10.1.2.0.1 r2
oracle application server 10.1.2.0.2 r2
oracle database server 10.2.0.1 r2
oracle database server 10.1.0.5 r1
oracle database server 9.2.0.7 r2
oracle e-business suite 11.5.10
oracle developer suite 6i
oracle database server 10.2.0.2 r2
oracle enterprise manager grid control 10.2.0.1
oracle application server 9.0.4.3
oracle peoplesoft enterprise peopletools 8.22
oracle peoplesoft enterprise peopletools 8.47
oracle peoplesoft enterprise peopletools 8.48
oracle developer suite 9.0.4.3
oracle developer suite 10.1.2.0.2
oracle database server 9.2.0.8 r2
oracle database server 10.2.0.3 r2
oracle identity management 10g 10.1.4.0.1
oracle e-business suite 11.5.7
oracle e-business suite 11.5.8
oracle e-business suite 11.5.9