Oracle / Banking Platform
72 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-43797 | HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling | MEDIUM | 6.5 | Dec 9, 2021 |
| CVE-2021-41184 | XSS in the `of` option of the `.position()` util | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2021-35043 | AntiSamy: XSS via HTML attributes | HIGH | 8.8 | Jul 19, 2021 |
| CVE-2021-36090 | Apache Commons Compress 1.0 to 1.20 denial of service vulnerability | HIGH | 7.5 | Jul 13, 2021 |
| CVE-2020-6950 | Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371 | HIGH | 7.5 | Jun 2, 2021 |
| CVE-2021-29425 | Possible limited path traversal vulnerabily in Apache Commons IO | MEDIUM | 4.8 | Apr 13, 2021 |
| CVE-2021-21348 | XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos) | HIGH | 7.5 | Mar 22, 2021 |
| CVE-2021-21349 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or… | HIGH | 8.6 | Mar 22, 2021 |
| CVE-2021-21350 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2021-21351 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.1 | Mar 22, 2021 |
| CVE-2021-21341 | XStream can cause a Denial of Service | HIGH | 7.5 | Mar 22, 2021 |
| CVE-2021-21342 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or… | CRITICAL | 9.1 | Mar 22, 2021 |
| CVE-2021-21343 | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights | HIGH | 7.5 | Mar 22, 2021 |
| CVE-2021-21344 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2021-21345 | XStream is vulnerable to a Remote Command Execution attack | CRITICAL | 9.9 | Mar 22, 2021 |
| CVE-2021-21346 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2021-21347 | XStream is vulnerable to an Arbitrary Code Execution attack | CRITICAL | 9.8 | Mar 22, 2021 |
| CVE-2020-13936 | Velocity Sandbox Bypass | HIGH | 8.8 | Mar 10, 2021 |
| CVE-2020-36189 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerC… | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-35490 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource | HIGH | 8.1 | Dec 17, 2020 |
| CVE-2020-35491 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource | HIGH | 8.1 | Dec 17, 2020 |
Showing 1 to 25 of 72 CVEs