CVE-2008-2138
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/...
- Published
- May 12, 2008
- Updated
- Aug 7, 2024
- Assigning CNA
- mitre
- Evidence observed
- May 9, 2008
Primary CVSS
nvd · CVSS 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:NModerate · next 30 days
- Percentile
- 96.7%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read the contents of /dav_portal/portal/ by sending a request containing a trailing "%0A" (encoded line feed), then using the session ID that is generated from that request. NOTE: as of 20080512, Oracle has not commented on the accuracy of this report.
Sources
1Deniz Cevik · multiple · May 9, 2008
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.