5
CVSSv2

CVE-2008-2138

Published: 12/05/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Oracle Application Server (OracleAS) Portal 10g allows remote malicious users to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle application server portal 10g

Exploits

source: wwwsecurityfocuscom/bid/29119/info Oracle Application Server Portal is prone to a authentication-bypass vulnerability because the application fails to properly restrict access to certain resources An attacker can exploit this vulnerability to bypass certain security restrictions and gain access to potentially sensitive contents ...