CVE-2008-2138
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 15.5%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 15.51% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- oracle/application server portal
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30140
- http://securityreason.com/securityalert/3867
- http://www.securityfocus.com/archive/1/491865/100/0/threaded
- http://www.securityfocus.com/bid/29119Exploit
- http://www.securitytracker.com/id?1020034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42302
- http://secunia.com/advisories/30140
- http://securityreason.com/securityalert/3867
- http://www.securityfocus.com/archive/1/491865/100/0/threaded
- http://www.securityfocus.com/bid/29119Exploit
- http://www.securitytracker.com/id?1020034
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42302
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.