CVE-2004-1362

critical

Description

The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access restrictions for certain procedures via an encoded URL with "%FF" encoded sequences that are improperly converted to "Y" characters.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/18657

http://www.us-cert.gov/cas/techalerts/TA04-245A.html

http://www.securityfocus.com/bid/10871

http://www.oracle.com/technology/deploy/security/pdf/2004alert68.pdf

http://www.ngssoftware.com/advisories/oracle23122004G.txt

http://www.kb.cert.org/vuls/id/435974

http://sunsolve.sun.com/search/document.do?assetkey=1-26-101782-1

http://marc.info/?l=bugtraq&m=110382306006205&w=2

Details

Source: Mitre, NVD

Published: 2004-08-04

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Severity: Critical