CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects Oracle. Its EPSS score suggests a 10.6% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2006-6697
Severity
HIGH
CVSS
7.5
EPSS
10.64%
Oracle
Original NVD Description
CRLF injection vulnerability in webapp/jsp/calendar.jsp in Oracle Portal 10g and earlier, including 9.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the enc parameter.