Oracle / Managed File Transfer
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-61003 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are… | CRITICAL | 9.9 | Aug 18, 2026 |
| CVE-2026-60549 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are… | HIGH | 8.8 | Jul 21, 2026 |
| CVE-2026-60547 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are… | CRITICAL | 9.9 | Jul 21, 2026 |
| CVE-2026-60545 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are… | HIGH | 8.8 | Jul 21, 2026 |
| CVE-2026-60537 | Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server). Supported versions that are affected are… | CRITICAL | 9.9 | Jul 21, 2026 |
| CVE-2022-23181 | Local privilege escalation with FileStore | HIGH | 7.0 | Jan 27, 2022 |
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-42340 | DoS via memory leak with WebSocket connections | HIGH | 7.5 | Oct 14, 2021 |
| CVE-2021-33037 | Incorrect Transfer-Encoding handling with HTTP/1.0 | MEDIUM | 5.3 | Jul 12, 2021 |
| CVE-2021-25329 | Incomplete fix for CVE-2020-9484 | HIGH | 7.0 | Mar 1, 2021 |
| CVE-2021-25122 | Apache Tomcat h2c request mix-up | HIGH | 7.5 | Mar 1, 2021 |
| CVE-2020-13935 | tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-13934 | tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-9484 | tomcat: deserialization flaw in session persistence storage leading to RCE | HIGH | 7.0 | May 20, 2020 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 6.1 | Nov 8, 2019 |
| CVE-2019-17359 | The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted… | HIGH | 7.5 | Oct 8, 2019 |
| CVE-2019-2538 | Vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware (subcomponent: MFT Runtime Server). Supported versions that are affecte… | HIGH | 7.1 | Jan 16, 2019 |
| CVE-2018-1000613 | bouncycastle: lack of class checking in deserialization of XMSS/XMSS^MT private keys with BDS state information | CRITICAL | 9.8 | Jul 9, 2018 |
| CVE-2018-1000180 | bouncycastle: flaw in the low-level interface to RSA key pair generator | HIGH | 7.5 | Jun 5, 2018 |
| CVE-2018-1305 | tomcat: Late application of security constraints can lead to resource exposure for unauthorised users | MEDIUM | 6.5 | Feb 23, 2018 |
Showing 1 to 20 of 20 CVEs