[
  {"cve_id":"CVE-2008-5720","description":"Cross-site scripting (XSS) vulnerability in Mayaa before 1.1.23 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the default error page for the org.seasar.mayaa.impl.engine.PageNotFoundException exception and possibly other exceptions.","exploit_maturity":"No public exploit","published":"2008-12-26","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2008-5414","description":"Unspecified vulnerability in the Feature Pack for Web Services in the Web Services Security component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 has unknown impact and attack vectors related to \"userNameToken.\"","exploit_maturity":"No public exploit","published":"2008-12-10","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5413","description":"PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 allows attackers to obtain sensitive information by reading the (1) systemout.log and (2) ffdc files.  NOTE: this is probably a duplicate of CVE-2009-0434.","exploit_maturity":"No public exploit","published":"2008-12-10","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-5412","description":"Unspecified vulnerability in IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 on Windows has unknown impact and attack vectors related to JSPs.  NOTE: this is probably a duplicate of CVE-2009-0438.","exploit_maturity":"No public exploit","published":"2008-12-10","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5411","description":"IBM WebSphere Application Server (WAS) 7 before 7.0.0.1 sends SSL traffic over \"unsecured TCP,\" which makes it easier for remote attackers to obtain sensitive information by sniffing the network.","exploit_maturity":"No public exploit","published":"2008-12-10","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-5360","description":"Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier creates temporary files with predictable file names, which allows attackers to write malicious JAR files via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-5355","description":"The \"Java Update\" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows remote attackers to execute arbitrary code via DNS man-in-the-middle attacks.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5353","description":"The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not properly enforce context of ZoneInfo objects during deserialization, which allows remote attackers to run untrusted applets and applications in a privileged context, as demonstrated by \"deserializing Calendar objects\".","exploit_maturity":"Working exploit published","published":"2008-12-05","resolved":"MITIGATED-BY-RASP","severity":"High"},
  {"cve_id":"CVE-2008-5351","description":"Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier accepts UTF-8 encodings that are not the \"shortest\" form, which makes it easier for attackers to bypass protection mechanisms for other applications that rely on shortest-form UTF-8 encodings.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5350","description":"Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applications and applets to list the contents of the operating user's directory via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-5349","description":"Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows remote attackers to cause a denial of service (CPU consumption) via a crafted RSA public key.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5348","description":"Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier, when using Kerberos authentication, allows remote attackers to cause a denial of service (OS resource consumption) via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5347","description":"Multiple unspecified vulnerabilities in Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier allow untrusted applets and applications to gain privileges via vectors related to access to inner classes in the (1) JAX-WS and (2) JAXB packages.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5346","description":"Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5345","description":"Unspecified vulnerability in Java Runtime Environment (JRE) with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 and earlier allows code that is loaded from a local filesystem to read arbitrary files and make unauthorized connections to localhost via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5344","description":"Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted applets to read arbitrary files and make unauthorized network connections via unknown vectors related to applet classloading, aka 6716217.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5343","description":"Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows remote attackers to make unauthorized network connections and hijack HTTP sessions via a crafted file that validates as both a GIF and a Java JAR file, aka \"GIFAR\" and CR 6707535.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5342","description":"Unspecified vulnerability in the BasicService for Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted downloaded applications to cause local files to be displayed in the browser of the user of the untrusted application via unknown vectors, aka 6767668.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-5341","description":"Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier, and JDK and JRE 5.0 Update 16 and earlier, allows untrusted JWS applications to obtain the pathname of the JWS cache and the application username via unknown vectors, aka CR 6727071.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-5340","description":"Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access local files or applications via unknown vectors, aka 6727081.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-5339","description":"Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to perform network connections to unauthorized hosts via unknown vectors, aka CR 6727079.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2086","description":"Sun Java Web Start and Java Plug-in for JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allow remote attackers to execute arbitrary code via a crafted jnlp file that modifies the (1) java.home, (2) java.ext.dirs, or (3) user.home System Properties, aka \"Java Web Start File Inclusion\" and CR 6694892.","exploit_maturity":"No public exploit","published":"2008-12-05","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"High"},
  {"cve_id":"CVE-2008-5266","description":"Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751.","exploit_maturity":"Working exploit published","published":"2008-11-28","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-4679","description":"The Web Services Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when Certificate Store Collections is configured to use Certificate Revocation Lists (CRL), does not call the setRevocationEnabled method on the PKIXBuilderParameters object, which prevents the \"Java security method\" from checking the revocation status of X.509 certificates and allows remote attackers to bypass intended access restrictions via a SOAP message with a revoked certificate.","exploit_maturity":"No public exploit","published":"2008-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-4678","description":"The HTTP_Request_Parser method in the HTTP Transport component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 allows remote attackers to cause a denial of service (controller 0C4 abend and application hang) via a long HTTP Host header, related to \"storage overlay\" on the stack and a \"parse failure.\"","exploit_maturity":"No public exploit","published":"2008-10-22","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-4004","description":"Unspecified vulnerability in the JDE EnterpriseOne Business Service Server component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.97.2.2 and 8.98.0.1 allows local users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-4003","description":"Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-4002","description":"Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote authenticated users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-4001","description":"Unspecified vulnerability in the PeopleSoft Enterprise Portal component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne EP 8.9 and EP 9.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-4000","description":"Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.18 and 8.49.14 allows remote attackers to affect confidentiality and integrity via unknown vectors.  NOTE: the previous information was obtained from the Oracle October 2008 CPU. Oracle has not commented on reliable researcher claims that this issue allows bypass of the lockout mechanism using brute force guessing of credentials and a response discrepancy information leak when the password is correct.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3998","description":"Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 12.0.4 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3993","description":"Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-3988","description":"Unspecified vulnerability in the iSupplier Portal component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote attackers to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3985","description":"Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.4 allows remote attackers to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2619","description":"Unspecified vulnerability in the Oracle Reports Developer component in Oracle Application Server 1.0.2.2, 9.0.4.3, and 10.1.2.2, and E-Business Suite 11.5.10.2, allows remote authenticated users to affect availability via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-2588","description":"Unspecified vulnerability in the Oracle JDeveloper component in Oracle Application Server 10.1.2.2 allows local users to affect confidentiality via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-10-14","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-3271","description":"Apache Tomcat 5.5.0 and 4.1.0 through 4.1.31 allows remote attackers to bypass an IP address restriction and obtain sensitive information via a request that is processed concurrently with another request but in a different thread, leading to an instance-variable overwrite associated with a \"synchronization problem\" and lack of thread safety, and related to RemoteFilterValve, RemoteAddrValve, and RemoteHostValve.","exploit_maturity":"No public exploit","published":"2008-10-13","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3519","description":"The default configuration of the JBossAs component in Red Hat JBoss Enterprise Application Platform (aka JBossEAP or EAP), possibly 4.2 before CP04 and 4.3 before CP02, when a production environment is enabled, sets the DownloadServerClasses property to true, which allows remote attackers to obtain sensitive information (non-EJB classes) via a download request, a different vulnerability than CVE-2008-3273.","exploit_maturity":"No public exploit","published":"2008-09-23","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-4111","description":"Unspecified vulnerability in Servlet Engine/Web Container in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.31 and 6.1 before 6.1.0.19, when the FileServing feature is enabled, has unknown impact and attack vectors.","exploit_maturity":"No public exploit","published":"2008-09-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-2938","description":"Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when allowLinking and UTF-8 are enabled, allows remote attackers to read arbitrary files via encoded directory traversal sequences in the URI, a different vulnerability than CVE-2008-2370.  NOTE: versions earlier than 6.0.18 were reported affected, but the vendor advisory lists 6.0.16 as the last affected version.","exploit_maturity":"Working exploit published","published":"2008-08-13","resolved":"MITIGATED-BY-RASP","severity":"Medium"},
  {"cve_id":"CVE-2008-2370","description":"Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.","exploit_maturity":"Working exploit published","published":"2008-08-04","resolved":"MITIGATED-BY-RASP","severity":"Medium"},
  {"cve_id":"CVE-2008-1232","description":"Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.","exploit_maturity":"Working exploit published","published":"2008-08-04","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-3236","description":"Unspecified vulnerability in Wsadmin in the System Management/Repository component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 allows attackers to obtain sensitive information via vectors related to \"previously encrypted properties\" that are not encrypted.","exploit_maturity":"No public exploit","published":"2008-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3235","description":"Unspecified vulnerability in the PropFilePasswordEncoder utility in the Security component in IBM WebSphere Application Server (WAS) 5.1 before 5.1.1.19 has unknown impact and attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-21","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-2622","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, and CVE-2008-2621.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2621","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, and CVE-2008-2622.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2620","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2621, and CVE-2008-2622.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2618","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2617, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2617","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2616, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2616","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2615, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2615","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.17 and 8.49.11 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2616, CVE-2008-2617, CVE-2008-2618, CVE-2008-2620, CVE-2008-2621, and CVE-2008-2622.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2612","description":"Unspecified vulnerability in the Hyperion BI Plus component in Oracle Application Server 8.3.2.4, 8.5.0.3, 9.2.0.3, 9.2.1.0, and 9.3.1.0 has unknown impact and remote attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2610","description":"Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2606","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2586.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2601","description":"Unspecified vulnerability in the Oracle iStore component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2596","description":"Unspecified vulnerability in the Mobile Application Server component in Oracle E-Business Suite 12.0.3 has unknown impact and remote authenticated attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2586","description":"Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2606.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2585","description":"Unspecified vulnerability in the Oracle Report Manager component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2582","description":"Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2581","description":"Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 has unknown impact and remote attack vectors related to UDDI Explorer.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2580","description":"Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, and 9.0 has unknown impact and remote attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2579","description":"Unspecified vulnerability in the WebLogic Server Plugins for Apache, Sun and IIS web servers component in Oracle BEA Product Suite 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, 7.0 SP7, and 6.1 SP7 has unknown impact and remote attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-2578","description":"Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 10.0 and 9.2 MP1 has unknown impact and local attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2577","description":"Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2 MP1 has unknown impact and remote authenticated attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-2576","description":"Unspecified vulnerability in the WebLogic Server component in Oracle BEA Product Suite 9.2, 9.1, 9.0, and 8.1 SP6 has unknown impact and local attack vectors.","exploit_maturity":"No public exploit","published":"2008-07-15","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3115","description":"Secure Static Versioning in Sun Java JDK and JRE 6 Update 6 and earlier, and 5.0 Update 6 through 15, does not properly prevent execution of applets on older JRE releases, which might allow remote attackers to exploit vulnerabilities in these older releases.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-3114","description":"Unspecified vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to obtain sensitive information (the cache location) via an untrusted application, aka CR 6704074.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3113","description":"Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"MITIGATED-BY-ENVIRONMENT","severity":"High"},
  {"cve_id":"CVE-2008-3112","description":"Directory traversal vulnerability in Sun Java Web Start in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create arbitrary files via the writeManifest method in the CacheEntry class, aka CR 6703909.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"MITIGATED-BY-RASP","severity":"High"},
  {"cve_id":"CVE-2008-3110","description":"Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to obtain sensitive information by using an applet to read information from another applet.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3109","description":"Unspecified vulnerability in scripting language support in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-3107","description":"Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-3106","description":"Unspecified vulnerability in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier allows remote attackers to access URLs via unknown vectors involving processing of XML data by an untrusted (1) application or (2) applet, a different vulnerability than CVE-2008-3105.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3105","description":"Unspecified vulnerability in the JAX-WS client and service in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier allows remote attackers to access URLs or cause a denial of service via unknown vectors involving \"processing of XML data\" by a trusted application.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-3104","description":"Multiple unspecified vulnerabilities in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allow remote attackers to violate the security model for an applet's outbound connections by connecting to localhost services running on the machine that loaded the applet.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-3103","description":"Unspecified vulnerability in the Java Management Extensions (JMX) management agent in Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 6 and earlier and JDK and JRE 5.0 Update 15 and earlier, when local monitoring is enabled, allows remote attackers to \"perform unauthorized operations\" via unspecified vectors.","exploit_maturity":"No public exploit","published":"2008-07-09","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-2751","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Glassfish webadmin interface in Sun Java System Application Server 9.1_01 allow remote attackers to inject arbitrary web script or HTML via the (1) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (2) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (3) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, or (4) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc parameter to (a) resourceNode/customResourceNew.jsf; the (5) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiProp:JndiNew, (6) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:resTypeProp:resType, (7) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:factoryClassProp:factoryClass, (8) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:jndiLookupProp:jndiLookup, or (9) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:descProp:desc parameter to (b) resourceNode/externalResourceNew.jsf; the (10) propertyForm:propertySheet:propertSectionTextField:jndiProp:Jndi, (11) propertyForm:propertySheet:propertSectionTextField:nameProp:name, or (12) propertyForm:propertySheet:propertSectionTextField:descProp:desc parameter to (c) resourceNode/jmsDestinationNew.jsf; the (13) propertyForm:propertySheet:generalPropertySheet:jndiProp:Jndi or (14) propertyForm:propertySheet:generalPropertySheet:descProp:cd parameter to (d) resourceNode/jmsConnectionNew.jsf; the (15) propertyForm:propertySheet:propertSectionTextField:jndiProp:jnditext or (16) propertyForm:propertySheet:propertSectionTextField:descProp:desc parameter to (e) resourceNode/jdbcResourceNew.jsf; the (17) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:nameProp:name, (18) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:classNameProp:classname, or (19) propertyForm:propertyContentPage:propertySheet:propertSectionTextField:loadOrderProp:loadOrder parameter to (f) applications/lifecycleModulesNew.jsf; or the (20) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:jndiProp:name, (21) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:resTypeProp:resType, or (22) propertyForm:propertyContentPage:propertySheet:generalPropertySheet:dbProp:db parameter to (g) resourceNode/jdbcConnectionPoolNew1.jsf.","exploit_maturity":"Working exploit published","published":"2008-06-18","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-2550","description":"Unspecified vulnerability in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.17 has unknown impact and attack vectors related to an attribute in the SOAP security header.","exploit_maturity":"No public exploit","published":"2008-06-04","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1947","description":"Cross-site scripting (XSS) vulnerability in Apache Tomcat 5.5.9 through 5.5.26 and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via the name parameter (aka the hostname attribute) to host-manager/html/add.","exploit_maturity":"No public exploit","published":"2008-06-04","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2008-2221","description":"Unspecified vulnerability in the Java plugin in IBM WebSphere Application Server 5.0.2 allows untrusted applets to gain privileges via unknown attack vectors.","exploit_maturity":"No public exploit","published":"2008-05-14","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-2120","description":"Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-05-09","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1831","description":"Multiple unspecified vulnerabilities in the Siebel SimBuilder component in Oracle Siebel Enterprise 7.8.2 and 7.8.5 have unknown impact and remote or local attack vectors, aka (1) SEBL01, (2) SEBL02, (3) SEBL03, (4) SEBL04, (5) SEBL05, and (6) SEBL06.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1830","description":"Unspecified vulnerability in the PeopleSoft HCM ePerformance component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.9 and 9.0 has unknown impact and remote attack vectors, aka PSE03.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1829","description":"Unspecified vulnerability in the PeopleSoft HCM Recruiting component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.8 SP1 has unknown impact and remote attack vectors, aka PSE02.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1828","description":"Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.19, 8.48.16, and 8.49.09 has unknown impact and remote authenticated attack vectors, aka PSE01.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1827","description":"Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 and 12.0.4 have unknown impact and attack vectors related to (a) Advanced Pricing component, aka (1) APP02, (2) APP03, and (3) APP09; (b) Application Object Library component, aka (4) APP04, (5) APP07, and (6) APP11; (c) Applications Manager component, aka (7) APP06; (d) and Applications Technology Stack component, aka (8) APP08.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1826","description":"Multiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka (1) APP01 and (2) APP10; and (b) Applications Framework, aka (3) APP05.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1822","description":"Unspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vectors, aka APEX02.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1811","description":"Unspecified vulnerability in Oracle Application Express 3.0.1 has unspecified impact and remote authenticated attack vectors related to flows_030000.wwv_execute_immediate, aka APEX01.  NOTE: the previous information was obtained from the April 2008 CPU.  Oracle has not commented on reliable researcher claims that APEX01 is for insufficient authorization checks for SQL commands in the run_ddl function in flows_030000.wwv_execute_immediate, allowing privilege escalation by certain non-DBA remote authenticated users.","exploit_maturity":"No public exploit","published":"2008-04-16","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1753","description":"Cross-site scripting (XSS) vulnerability in system/workplace/admin/workplace/sessions.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the searchfilter parameter, a different vector than CVE-2008-1510.","exploit_maturity":"No public exploit","published":"2008-04-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2008-1728","description":"ConnectionManagerImpl.java in Ignite Realtime Openfire 3.4.5 allows remote authenticated users to cause a denial of service (daemon outage) by triggering large outgoing queues without reading messages.","exploit_maturity":"No public exploit","published":"2008-04-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2008-1510","description":"Cross-site scripting (XSS) vulnerability in system/workplace/admin/accounts/users_list.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the (1) searchfilter or (2) listSearchFilter parameter.","exploit_maturity":"Working exploit published","published":"2008-03-25","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-1357","description":"Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082.  NOTE: this issue only exists when the debug level is 8.","exploit_maturity":"Working exploit published","published":"2008-03-17","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-1301","description":"Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote authenticated administrators to read arbitrary files via a full pathname in the filePath.0 parameter.","exploit_maturity":"Working exploit published","published":"2008-03-12","resolved":"MITIGATED-BY-RASP","severity":"Medium"},
  {"cve_id":"CVE-2008-1300","description":"Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon OpenCms 7.0.3 and 7.0.4 allows remote attackers to inject arbitrary web script or HTML via the filePath.0 parameter in a save action, a different vector than CVE-2008-1045.","exploit_maturity":"Working exploit published","published":"2008-03-12","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-1285","description":"Cross-site scripting (XSS) vulnerability in Sun Java Server Faces (JSF) 1.2 before 1.2_08 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-03-11","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2008-1194","description":"Multiple unspecified vulnerabilities in the color management library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to cause a denial of service (crash) via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1193","description":"Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier, allows remote attackers to gain privileges via an untrusted application.","exploit_maturity":"Working exploit published","published":"2008-03-06","resolved":"MITIGATION-CANDIDATE","severity":"High"},
  {"cve_id":"CVE-2008-1192","description":"Unspecified vulnerability in the Java Plug-in for Sun JDK and JRE 6 Update 4 and earlier, and 5.0 Update 14 and earlier; and SDK and JRE 1.4.2_16 and earlier, and 1.3.1_21 and earlier; allows remote attackers to bypass the same origin policy and \"execute local applications\" via unknown vectors.","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1191","description":"Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier allows remote attackers to create arbitrary files via an untrusted application, a different issue than CVE-2008-1190, aka \"The fifth issue.\"","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1190","description":"Unspecified vulnerability in Java Web Start in Sun JDK and JRE 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application, a different issue than CVE-2008-1191, aka the \"fourth\" issue.","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1187","description":"Unspecified vulnerability in Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to cause a denial of service (JRE crash) and possibly execute arbitrary code via unknown vectors related to XSLT transforms.","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-1186","description":"Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 5.0 Update 13 and earlier, and SDK/JRE 1.4.2_16 and earlier, allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1185, aka \"the second issue.\"","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1185","description":"Unspecified vulnerability in the Virtual Machine for Sun Java Runtime Environment (JRE) and JDK 6 Update 4 and earlier, 5.0 Update 14 and earlier, and SDK/JRE 1.4.2_16 and earlier allows remote attackers to gain privileges via an untrusted application or applet, a different issue than CVE-2008-1186, aka \"the first issue.\"","exploit_maturity":"No public exploit","published":"2008-03-06","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-1045","description":"Cross-site scripting (XSS) vulnerability in the file tree navigation function in system/workplace/views/explorer/tree_files.jsp in Alkacon OpenCMS 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the resource parameter.","exploit_maturity":"Working exploit published","published":"2008-02-27","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-0741","description":"Unspecified vulnerability in the PropFilePasswordEncoder utility in IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) has unknown impact and attack vectors.","exploit_maturity":"No public exploit","published":"2008-02-13","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-0740","description":"IBM WebSphere Application Server (WAS) before 6.0.2 Fix Pack 25 (6.0.2.25) and 6.1 before Fix Pack 15 (6.1.0.15) writes unspecified cleartext information to http_plugin.log, which might allow local users to obtain sensitive information by reading this file.","exploit_maturity":"No public exploit","published":"2008-02-13","resolved":"NO-FIX-IDENTIFIED","severity":"Low"},
  {"cve_id":"CVE-2008-0002","description":"Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.","exploit_maturity":"No public exploit","published":"2008-02-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2007-6286","description":"Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of \"a duplicate copy of one of the recent requests,\" as demonstrated by using netcat to send the empty request.","exploit_maturity":"No public exploit","published":"2008-02-12","resolved":"NO-EXPLOIT-PUBLISHED","severity":"Medium"},
  {"cve_id":"CVE-2007-5333","description":"Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (\") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.  NOTE: this issue exists because of an incomplete fix for CVE-2007-3385.","exploit_maturity":"Working exploit published","published":"2008-02-12","resolved":"MITIGATION-CANDIDATE","severity":"Medium"},
  {"cve_id":"CVE-2008-0657","description":"Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstrated by an application or applet that grants itself privileges to (a) read local files, (b) write to local files, or (c) execute local programs.","exploit_maturity":"No public exploit","published":"2008-02-07","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-0628","description":"The XML parsing code in Sun Java Runtime Environment JDK and JRE 6 Update 3 and earlier processes external entity references even when the \"external general entities\" property is false, which allows remote attackers to conduct XML external entity (XXE) attacks and cause a denial of service or access restricted resources.","exploit_maturity":"No public exploit","published":"2008-02-06","resolved":"MITIGATED-BY-RASP","severity":"High"},
  {"cve_id":"CVE-2008-0389","description":"Unspecified vulnerability in the serveServletsByClassnameEnabled feature in IBM WebSphere Application Server (WAS) 6.0 through 6.0.2.25, 6.1 through 6.1.0.14, and 5.1.1.x before 5.1.1.18 has unknown impact and attack vectors.","exploit_maturity":"No public exploit","published":"2008-01-23","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-0128","description":"The SingleSignOn Valve (org.apache.catalina.authenticator.SingleSignOn) in Apache Tomcat before 5.5.21 does not set the secure flag for the JSESSIONIDSSO cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie.","exploit_maturity":"No public exploit","published":"2008-01-23","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2008-0349","description":"Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.48.15 and 8.49.07 has unknown impact and remote attack vectors, aka PSE02.","exploit_maturity":"No public exploit","published":"2008-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-0348","description":"Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.","exploit_maturity":"No public exploit","published":"2008-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-0347","description":"Unspecified vulnerability in the Oracle Ultra Search component in Oracle Collaboration Suite 10.1.2; Database 9.2.0.8, 10.1.0.5, and 10.2.0.3; and Application Server 9.0.4.3 and 10.1.2.0.2; has unknown impact and local attack vectors, aka OCS01.  NOTE: Oracle has not disputed a reliable claim that this issue is related to WKSYS schema privileges.","exploit_maturity":"No public exploit","published":"2008-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2008-0346","description":"Unspecified vulnerability in the Oracle Jinitiator component in Oracle Application Server 1.3.1.27 and E-Business Suite 11.5.10.2 has unknown impact and remote attack vectors, aka AS01.","exploit_maturity":"No public exploit","published":"2008-01-17","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2007-6679","description":"Unspecified vulnerability in the Administrative Console in IBM WebSphere Application Server 6.1 before Fix Pack 13 has unknown impact and attack vectors, related to \"security concerns with monitor role users.\"  NOTE: it was later reported that 6.0.2 before Fix Pack 25 is also affected.","exploit_maturity":"No public exploit","published":"2008-01-10","resolved":"NO-FIX-IDENTIFIED","severity":"High"},
  {"cve_id":"CVE-2007-0012","description":"Sun JRE 5.0 before update 14 allows remote attackers to cause a denial of service (Internet Explorer crash) via an object tag with an encoded applet and an undefined name attribute, which triggers a NULL pointer dereference in jpiexp32.dll when the applet is decoded and passed to the JVM.","exploit_maturity":"No public exploit","published":"2008-01-09","resolved":"NO-FIX-IDENTIFIED","severity":"Medium"},
  {"cve_id":"CVE-2007-6672","description":"Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.","exploit_maturity":"No public exploit","published":"2008-01-08","resolved":"MITIGATED-BY-RASP","severity":"Medium"}
]
