This page lists publicly disclosed CVE vulnerabilities affecting oracle application_server (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2009-1009 | Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.1.9 allows local users to affect confidentiality, integrity, and availability, related to HTML. | [email protected] | 4.4 | 0.42% | 2009-04-15 | 2026-06-16 |
| CVE-2009-1008 | Unspecified vulnerability in the Outside In Technology component in Oracle Application Server 8.2.2 and 8.3.0 allows local users to affect confidentiality, integrity, and availability, related to HTML, a different vulnerability than CVE-2009-1010. | [email protected] | 4.4 | 0.42% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0996 | Unspecified vulnerability in the BI Publisher component in Oracle Application Server 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors. | [email protected] | 4.0 | 2.54% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0994 | Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, 10.1.3.3.3, and 10.1.3.4 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2009-1017. | [email protected] | 4.0 | 2.59% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0993 | Unspecified vulnerability in the OPMN component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the April 2009 CPU. Oracle has not commented on reliable researcher claims that this issue is a format string vulnerability that allows remote attackers to execute arbitrary code via format string specifiers in an HTTP POST URI, which are not properly handled whe | [email protected] | 7.5 | 7.95% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0990 | Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0989. | [email protected] | 5.5 | 2.59% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0989 | Unspecified vulnerability in the BI Publisher component in Oracle Application Server 5.6.2, 10.1.3.2.1, and 10.1.3.3.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2009-0990. | [email protected] | 5.5 | 2.59% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0983 | Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0974 and CVE-2009-3407. | [email protected] | 4.3 | 2.67% | 2009-04-15 | 2026-06-16 |
| CVE-2009-0974 | Unspecified vulnerability in the Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2009-0983 and CVE-2009-3407. | [email protected] | 4.3 | 2.94% | 2009-04-15 | 2026-06-16 |
| CVE-2008-5438 | Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 allows remote attackers to affect integrity via unknown vectors. | [email protected] | 4.3 | 2.15% | 2009-01-13 | 2026-06-16 |
| CVE-2008-4017 | Unspecified vulnerability in the OC4J component in Oracle Application Server 10.1.2.3 allows remote attackers to affect confidentiality via unknown vectors. | [email protected] | 5.0 | 1.31% | 2009-01-13 | 2026-06-16 |
| CVE-2008-4014 | Unspecified vulnerability in the Oracle BPEL Process Manager component in Oracle Application Server allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | [email protected] | 5.5 | 1.02% | 2009-01-13 | 2026-06-16 |
| CVE-2008-3987 | Unspecified vulnerability in the Oracle Discoverer Desktop component in Oracle Application Server 10.1.2.3 allows local users to affect confidentiality via unknown vectors. | [email protected] | 1.0 | 0.27% | 2008-10-14 | 2026-06-16 |
| CVE-2008-3986 | Unspecified vulnerability in the Oracle Discoverer Administrator component in Oracle Application Server 9.0.4.3 and 10.1.2.2 allows local users to affect confidentiality via unknown vectors. | [email protected] | 1.0 | 0.27% | 2008-10-14 | 2026-06-16 |
| CVE-2008-3977 | Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3975. | [email protected] | 5.0 | 1.55% | 2008-10-14 | 2026-06-16 |
| CVE-2008-3975 | Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3 and 10.1.2.3 allows remote attackers to affect integrity via unknown vectors, a different vulnerability than CVE-2008-3977. | [email protected] | 5.0 | 1.55% | 2008-10-14 | 2026-06-16 |
| CVE-2008-2619 | Unspecified vulnerability in the Oracle Reports Developer component in Oracle Application Server 1.0.2.2, 9.0.4.3, and 10.1.2.2, and E-Business Suite 11.5.10.2, allows remote authenticated users to affect availability via unknown vectors. | [email protected] | 1.7 | 0.54% | 2008-10-14 | 2026-06-16 |
| CVE-2008-2614 | Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.3.3 has unknown impact and remote attack vectors. | [email protected] | 4.3 | 1.14% | 2008-07-15 | 2026-06-16 |
| CVE-2008-2609 | Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.4.2 has unknown impact and remote attack vectors. | [email protected] | 6.4 | 1.29% | 2008-07-15 | 2026-06-16 |
| CVE-2008-2593 | Unspecified vulnerability in the Oracle Portal component in Oracle Application Server 10.1.2.3 and 10.1.4.2 has unknown impact and remote attack vectors, a different vulnerability than CVE-2008-2594. | [email protected] | 4.3 | 1.66% | 2008-07-15 | 2026-06-16 |