Application Server
Vendor:
First CVE: Mar 15, 2000 · Active for 26 years
199
Total CVEs
More Total CVEs than 99% of tracked products
15.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Application Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2000
26 years ago
Most Recent CVE
Apr 21, 2020
2,285 days ago
CVE Severity & Scoring
Application Server199 CVEs
39%
53%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.5%)
Network3 (1.5%)
Unknown195 (98.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (1.0%)
High2 (1.0%)
Unknown195 (98.0%)
User Interaction
None4 (2.0%)
Unknown195 (98.0%)
Required0 (0.0%)
Privileges Required
Low1 (0.5%)
High0 (0.0%)
None3 (1.5%)
Unknown195 (98.0%)
Top CVEs
Signals from CVEs in this product scope (199 CVEs).
199 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0656HIGH Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary code via (1) a large client master key in SSL2 or (2) a lar | Aug 12, 2002 | 7.5 | 81 | NO | YES |
CVE-2002-0840MEDIUM Cross-site scripting (XSS) vulnerability in the default error page of Apache 2.0 before 2.0.43, and 1.3.x up to 1.3.26, when UseCanonicalName is "Off" and support for wildcard DNS | Oct 11, 2002 | 6.8 | 78 | NO | YES |
CVE-2020-1967HIGH Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect hand | Apr 21, 2020 | 7.5 | 51 | NO | NO |
CVE-2006-0287HIGH Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as ide | Jan 18, 2006 | 10.0 | 50 | NO | YES |
Oracle 9i Application Server stores XSQL and SOAP configuration files insecurely, which allows local users to obtain sensitive information including usernames and passwords by requ | Jul 3, 2002 | 2.1 | 49 | NO | NO |
CVE-2001-0419HIGH Buffer overflow in shared library ndwfn4.so for iPlanet Web Server (iWS) 4.1, when used as a web listener for Oracle application server 4.0.8.2, allows remote attackers to execute | Jul 2, 2001 | 7.5 | 47 | NO | YES |
CVE-2005-1383HIGH The OHS component 1.0.2 through 10.x, when UseWebcacheIP is disabled, in Oracle Application Server allows remote attackers to bypass HTTP Server mod_access restrictions via a reque | May 3, 2005 | 7.5 | 44 | NO | YES |
CVE-2002-0563MEDIUM The default configuration of Oracle 9i Application Server 1.0.2.x allows remote anonymous users to access sensitive services without authentication, including Dynamic Monitoring Se | Jul 3, 2002 | 5.0 | 44 | NO | NO |
CVE-2000-0169HIGH Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL that includes '?&'. | Mar 15, 2000 | 7.5 | 42 | NO | YES |
CVE-2002-0659MEDIUM The ASN1 library in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allows remote attackers to cause a denial of service via invalid encodings. | Aug 12, 2002 | 5.0 | 40 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (199 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
8.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (199 CVEs).
Media Mentions
Signals from CVEs in this product scope (199 CVEs).
Top CNAs Publishing CVEs For Application Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| release_1.0.2.0.1 | 1 | 7.5 | 5.3% | 0 | 0 |
| 9.2.0.7 | 2 | 6.5 | 3.9% | 0 | 0 |
| 9.2.0.6 | 3 | 5.8 | 9.5% | 0 | 1 |
| 9.0.4.3 | 49 | 7.5 | 2.2% | 0 | 0 |
| 9.0.4.2 | 25 | 9.1 | 4.9% | 0 | 0 |
| 9.0.4.1 | 23 | 7.6 | 6.4% | 0 | 1 |
| 9.0.4.0 | 12 | 6.8 | 8.0% | 0 | 1 |
| 9.0.4 | 12 | 6.8 | 7.8% | 0 | 1 |
| 9.0.3.1 | 28 | 7.3 | 6.5% | 0 | 3 |
| 9.0.3 | 17 | 6.2 | 7.4% | 0 | 4 |
| 9.0.2.3 | 29 | 7.2 | 6.3% | 0 | 4 |
| 9.0.2.2 | 16 | 6.3 | 7.7% | 0 | 4 |
| 9.0.2.1 | 19 | 6.6 | 12.9% | 0 | 5 |
| 9.0.2.0.1 | 20 | 6.3 | 7.4% | 0 | 4 |
| 9.0.2.0.0 | 20 | 6.3 | 7.4% | 0 | 4 |
| 9.0.2 | 26 | 6.2 | 14.5% | 0 | 7 |
| 9.0 | 6 | 9.3 | 4.6% | 0 | 0 |
| 8.3.0 | 3 | 4.4 | 0.4% | 0 | 0 |
| 8.2.2 | 3 | 4.4 | 0.4% | 0 | 0 |
| 8.1.9 | 1 | 4.4 | 0.4% | 0 | 0 |