Oracle / Policy Automation
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-44832 | Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration | MEDIUM | 6.6 | Dec 28, 2021 |
| CVE-2021-41184 | XSS in the `of` option of the `.position()` util | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41183 | XSS in `*Text` options of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-41182 | XSS in the `altField` option of the Datepicker widget | MEDIUM | 6.5 | Oct 26, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2020-11022 | jQuery has a potential XSS vulnerability | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-9488 | log4j: improper validation of certificate with host mismatch in SMTP appender | LOW | 3.7 | Apr 27, 2020 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 6.1 | Nov 8, 2019 |
| CVE-2019-17195 | nimbus-jose-jwt: Uncaught exceptions while parsing a JWT | CRITICAL | 9.8 | Oct 15, 2019 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
| CVE-2017-5645 | log4j: Socket receiver deserialization vulnerability | CRITICAL | 9.8 | Apr 17, 2017 |
Showing 1 to 11 of 11 CVEs