Sun / Java System Application Server
22 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2012-3155 | Unspecified vulnerability in the CORBA ORB component in Sun GlassFish Enterprise Server 2.1.1, Oracle GlassFish Server 3.0.1 and 3.1.2, and Sun Java System App… | MEDIUM | 5.0 | Oct 16, 2012 |
| CVE-2011-0807 | Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Application Server 9.1, allows remote attackers… | HIGH | 10.0 | Apr 20, 2011 |
| CVE-2010-0386 | The default configuration of Sun Java System Application Server 7 and 7 2004Q2 enables the HTTP TRACE method, which makes it easier for remote attackers to ste… | HIGH | 8.1 | Jan 25, 2010 |
| CVE-2009-0278 | Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF… | MEDIUM | 5.0 | Jan 27, 2009 |
| CVE-2008-5266 | Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Ser… | MEDIUM | 4.3 | Nov 28, 2008 |
| CVE-2008-2751 | Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to… | MEDIUM | 4.3 | Jun 18, 2008 |
| CVE-2008-2120 | Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows… | MEDIUM | 5.0 | May 9, 2008 |
| CVE-2007-5153 | Unspecified vulnerability in Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 8.x container, allows remote attackers… | MEDIUM | 6.8 | Oct 1, 2007 |
| CVE-2007-5152 | Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container rest… | HIGH | 7.5 | Oct 1, 2007 |
| CVE-2007-4511 | The Sun Admin Console in Sun Application Server 9.0_0.1 does not apply certain configuration changes persistently, which causes the (1) SSL and (2) SSL_MutualA… | MEDIUM | 5.0 | Aug 23, 2007 |
| CVE-2007-4025 | Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source c… | MEDIUM | 4.3 | Jul 26, 2007 |
| CVE-2007-3715 | Sun Java System Application Server and Web Server 7.0 through 9.0 before 20070710 do not properly process XSLT stylesheets in XSLT transforms in XML signatures… | HIGH | 9.3 | Jul 11, 2007 |
| CVE-2006-6276 | HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used with Sun Java System Application Server or Sun Java System Web… | MEDIUM | 6.8 | Dec 4, 2006 |
| CVE-2006-3921 | Sun Java System Application Server (SJSAS) 7 through 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "doc… | MEDIUM | 4.0 | Jul 28, 2006 |
| CVE-2006-3225 | Cross-site scripting (XSS) vulnerability in Sun ONE Application Server 7 before Update 9, Java System Application Server 7 2004Q2 before Update 5, and Java Sys… | LOW | 2.6 | Jun 26, 2006 |
| CVE-2005-4805 | Unspecified vulnerability in Sun Java System Application Server 7 Standard and Platform Edition 6 and earlier, and 2004Q2 Standard and Platform Edition Update… | MEDIUM | 5.0 | May 25, 2006 |
| CVE-2005-4804 | Unspecified vulnerability in Sun Java System Application Server Platform Edition and Enterprise Edition 8.1 2005 Q1, and Platform Edition UR1, allows remote at… | MEDIUM | 5.0 | May 25, 2006 |
| CVE-2006-2501 | Cross-site scripting (XSS) vulnerability in Sun ONE Web Server 6.0 SP9 and earlier, Java System Web Server 6.1 SP4 and earlier, Sun ONE Application Server 7 Pl… | MEDIUM | 6.8 | May 20, 2006 |
| CVE-2005-4046 | Unspecified vulnerability in Reverse SSL Proxy Plug-in for Sun Java System Application Server Standard Edition 7 2004Q2, Application Server Enterprise Edition… | MEDIUM | 4.0 | Dec 7, 2005 |
| CVE-2004-2216 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote a… | MEDIUM | 5.0 | Jul 17, 2005 |
| CVE-2005-0742 | Cross-site scripting (XSS) vulnerability in Sun Java System Application Server 7 allows remote attackers to inject arbitrary web script or HTML via unknown vec… | MEDIUM | 4.3 | Mar 13, 2005 |
| CVE-2004-0826 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length f… | HIGH | 7.5 | Sep 2, 2004 |
Showing 1 to 22 of 22 CVEs