VulnerabilityModified
CVE-2005-4550
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).
MEDIUM 5.0EPSS 6.09%
Does this matter?
Lower severity and a low EPSS score (6.09%). Track it; it rarely justifies an emergency change on its own.
Description
The PORTAL schema in Oracle Application Server (OracleAS) Discussion Forum Portlet allows remote attackers to obtain the source code for arbitrary JSP and other files via a df_next_page parameter with a trailing null byte (%00).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 6.09% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- oracle/application server discussion forum portlet
- Source
- cve@mitre.org
References
- http://marc.info/?l=full-disclosure&m=113532633229270&w=2
- http://securityreason.com/securityalert/297
- http://securitytracker.com/id?1015406
- http://www.securityfocus.com/bid/16048Exploit
- http://www.vupen.com/english/advisories/2005/3085
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23813
- http://marc.info/?l=full-disclosure&m=113532633229270&w=2
- http://securityreason.com/securityalert/297
- http://securitytracker.com/id?1015406
- http://www.securityfocus.com/bid/16048Exploit
- http://www.vupen.com/english/advisories/2005/3085
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23813
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.