« Volver al listado

CVE-2003-0633

Estado: ModificadaMedia (5)—

Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2003-0633",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2003-08-27T04:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=105906689120237&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/8268",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=105906689120237&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://otn.oracle.com/deploy/security/pdf/2003alert55.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/8268",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple vulnerabilities in aoljtest.jsp of Oracle Applications AOL/J Setup Test Suite in Oracle E-Business Suite 11.5.1 through 11.5.8 allow a remote attacker to obtain sensitive information without authentication, such as the GUEST user password and the application server security key."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades en aoljtest.jsp de Oracle Applications AOL/J Setup Test Suite en Oracle E-Business Suite 11.5.1 a  11.5.8 permite a atacantes remotos obtener información sensible sin autenticarse, como la contraseña del usuario GUEST y la clave de seguridad del servidor de aplicaciones."
    }
  ],
  "lastModified": "2026-06-16T22:02:33.427",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:applications:10.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5C5CA794-B708-4107-BAAC-8F3E005BFFDB"
            },
            {
              "criteria": "cpe:2.3:a:oracle:applications:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A1457AD-2BB0-46BE-850C-6B5D9A12FE58"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34112DA5-C0B6-46E9-A69F-02F24BDBA6ED"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6883CFF-B2CB-4B75-8E6B-938A78CF7DFA"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9134636B-0CF6-41BE-8C5F-BB6C0C55A199"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B512964-2367-4C55-BB75-9EBFB3707179"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1DC2C3EF-B1A4-4BF9-B534-A7ABB6490CCF"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BC900808-1118-4FC0-9E48-380A02394F45"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD00F5CD-125C-4895-824E-23AC1D9A34BF"
            },
            {
              "criteria": "cpe:2.3:a:oracle:e-business_suite:11.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FE95D02-C2A8-4AAC-878B-DFA0FE13B571"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}