SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2004-1362

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures…

HIGH 7.5EPSS 9.05%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (9.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
9.05% probability · 95th percentile
CISA KEV
Not listed
Affected
oracle/application server · oracle/collaboration suite · oracle/e-business suite · oracle/enterprise manager · oracle/enterprise manager database control · oracle/enterprise manager grid control · oracle/oracle10g · oracle/oracle8i · oracle/oracle9i
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.