CVE-2004-1362
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.05%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 9.05% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server · oracle/collaboration suite · oracle/e-business suite · oracle/enterprise manager · oracle/enterprise manager database control · oracle/enterprise manager grid control · oracle/oracle10g · oracle/oracle8i · oracle/oracle9i
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=110382306006205&w=2
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
- http://www.kb.cert.org/vuls/id/435974Third Party Advisory, US Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004G.txtPatch, Vendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfPatch, Vendor Advisory
- http://www.securityfocus.com/bid/10871Patch
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18657
- http://marc.info/?l=bugtraq&m=110382306006205&w=2
- http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1
- http://www.kb.cert.org/vuls/id/435974Third Party Advisory, US Government Resource
- http://www.ngssoftware.com/advisories/oracle23122004G.txtPatch, Vendor Advisory
- http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdfPatch, Vendor Advisory
- http://www.securityfocus.com/bid/10871Patch
- http://www.us-cert.gov/cas/techalerts/TA04-245A.htmlPatch, Third Party Advisory, US Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18657
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.