Oracle / Endeca Information Discovery Integrator
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-5421 | RFD Protection Bypass via jsessionid | MEDIUM | 6.5 | Sep 19, 2020 |
| CVE-2020-10683 | dom4j: XML External Entity vulnerability in default SAX parser | CRITICAL | 9.8 | May 1, 2020 |
| CVE-2019-10247 | jetty: error path information disclosure | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2019-10246 | jetty: Directory Listing on Windows reveals Resource Base path | MEDIUM | 5.3 | Apr 22, 2019 |
| CVE-2018-15756 | DoS Attack via Range Requests | HIGH | 7.5 | Oct 18, 2018 |
| CVE-2018-3215 | Vulnerability in the Oracle Endeca Information Discovery Integrator component of Oracle Fusion Middleware (subcomponent: Integrator ETL). Supported versions th… | MEDIUM | 5.4 | Oct 17, 2018 |
| CVE-2018-11040 | springframework: cross-domain requests via JSONP through AbstractJsonpResponseBodyAdvice | HIGH | 7.5 | Jun 25, 2018 |
| CVE-2018-11039 | springframework: Cross Site Tracing (XST) if vulnerable to XSS | MEDIUM | 5.9 | Jun 25, 2018 |
| CVE-2018-1258 | spring-security-core: Unauthorized Access with Spring Security Method Security | HIGH | 8.8 | May 11, 2018 |
| CVE-2018-1257 | spring-framework: ReDoS Attack with spring-messaging | MEDIUM | 6.5 | May 11, 2018 |
| CVE-2017-12617 KEV | tomcat: Remote Code Execution bypass for CVE-2017-12615 | HIGH | 8.1 | Oct 3, 2017 |
Showing 1 to 11 of 11 CVEs