threat
engine
.sh
Back
·
··:··
Home
/
Product
/
oracle reports
Product
oracle reports
10 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-29885
< 5.2.3
silverstripe/reports is an API for creating backend reports in the Silverstripe Framework. In affected versions reports can be acc
4.3
MEDIUM
CVE-2022-39181
all versions
GLPI - Reports plugin for GLPI Reflected Cross-Site-Scripting (RXSS). Type 1: Reflected XSS (or Non-Persistent) - The server reads
6.1
MEDIUM
CVE-2021-42777
all versions
Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0, when Compilation Mode is used, allows an attacker to execute arbitrary C# code
9.8
CRITICAL
CVE-2020-15865
all versions
A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts
9.8
CRITICAL
CVE-2005-2983
all versions
SQL injection vulnerability in Oracle Reports that use Lexical References allows remote attackers to execute arbitrary SQL command
CVE-2005-2379
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Reports 9.0.2 allow remote attackers to inject arbitrary web script
CVE-2005-2378
all versions
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative pa
CVE-2005-2371
all versions
Directory traversal vulnerability in Oracle Reports 6.0, 6i, 9i, and 10g allows remote attackers to overwrite arbitrary files via
CVE-2002-1089
all versions
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could ena
CVE-2002-0947
all versions
Buffer overflow in rwcgi60 CGI program for Oracle Reports Server 6.0.8.18.0 and earlier, as used in Oracle9iAS and other products,
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin