Oracle / JD Edwards Enterpriseone Orchestrator
46 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-61270 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are… | HIGH | 8.1 | Aug 18, 2026 |
| CVE-2026-61265 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are… | HIGH | 8.1 | Aug 18, 2026 |
| CVE-2025-21552 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are… | MEDIUM | 6.5 | Jan 21, 2025 |
| CVE-2024-21168 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are… | MEDIUM | 6.5 | Jul 16, 2024 |
| CVE-2023-22050 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). Supported versions that are… | MEDIUM | 5.4 | Jul 18, 2023 |
| CVE-2022-21532 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator). Supported versions that are affected… | MEDIUM | 4.3 | Jul 19, 2022 |
| CVE-2021-2052 | Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of Oracle JD Edwards (component: E1 IOT Orchestrator Security). The supported version that i… | MEDIUM | 5.8 | Jan 20, 2021 |
| CVE-2020-36179 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36180 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36182 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36183 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36184 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36185 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36186 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36187 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36188 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnection… | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36189 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerC… | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36181 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-35728 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnection… | HIGH | 8.1 | Dec 27, 2020 |
| CVE-2020-17521 | groovy: OS temporary directory leads to information disclosure | MEDIUM | 5.5 | Dec 7, 2020 |
| CVE-2020-25649 | jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) | HIGH | 7.5 | Dec 3, 2020 |
| CVE-2020-13956 | apache-httpclient: incorrect handling of malformed authority component in request URIs | MEDIUM | 5.3 | Dec 2, 2020 |
| CVE-2020-11023 KEV | Potential XSS vulnerability in jQuery | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-11620 | jackson-databind: Serialization gadgets in commons-jelly:commons-jelly | HIGH | 8.1 | Apr 7, 2020 |
| CVE-2020-11619 | jackson-databind: Serialization gadgets in org.springframework:spring-aop | HIGH | 8.1 | Apr 7, 2020 |
Showing 1 to 25 of 46 CVEs