CVE-2004-1877 describes a spoofing vulnerability in the sample login form of the Oracle 9i Application Server (9iAS) Single Sign-on Administrators Guide, Release 2 (9.0.2) for Oracle SSO, affecting Oracle Application Server and Oracle HTTP Server. The vulnerability, with a CVSS score of 2.6, allows remote attackers to spoof the login page due to an issue with the p_submit_url value, potentially leading to users inadvertently revealing their credentials. While the attack complexity is high, the potential impact is a partial loss of confidentiality. There is no evidence of active exploitation, no known exploit code (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2:*:*:*:*:*:*:* | ||
1.0.2.1sCPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2.1s:*:*:*:*:*:*:* | ||
1.0.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2.2:*:*:*:*:*:*:* | ||
1.0.2.2.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:1.0.2.2.2:*:*:*:*:*:*:* | ||
9.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_server:9.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:H/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.