Oracle / Retail Central Office
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2021-35043 | AntiSamy: XSS via HTML attributes | HIGH | 8.8 | Jul 19, 2021 |
| CVE-2021-36374 | Apache Ant ZIP, and ZIP based, archive denial of service vulerability | MEDIUM | 5.5 | Jul 14, 2021 |
| CVE-2021-36373 | Apache Ant TAR archive denial of service vulnerability | MEDIUM | 5.5 | Jul 14, 2021 |
| CVE-2020-11987 | batik: SSRF due to improper input validation by the NodePickerPanel | HIGH | 8.2 | Feb 24, 2021 |
| CVE-2020-1945 | ant: insecure temporary file vulnerability | MEDIUM | 6.3 | May 14, 2020 |
| CVE-2020-5397 | CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux | MEDIUM | 5.3 | Jan 17, 2020 |
| CVE-2020-5398 | RFD Attack via "Content-Disposition" Header Sourced from Request Input by Spring MVC or Spring WebFlux Application | HIGH | 8.0 | Jan 16, 2020 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 6.1 | Nov 8, 2019 |
| CVE-2019-10086 | apache-commons-beanutils: does not suppresses the class property in PropertyUtilsBean by default | HIGH | 7.3 | Aug 20, 2019 |
| CVE-2019-13990 | libquartz: XXE attacks via job description | CRITICAL | 9.8 | Jul 26, 2019 |
| CVE-2019-11358 | jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection | MEDIUM | 6.1 | Apr 19, 2019 |
| CVE-2018-8013 | batik: information disclosure when deserializing | CRITICAL | 9.8 | May 24, 2018 |
| CVE-2018-1258 | spring-security-core: Unauthorized Access with Spring Security Method Security | HIGH | 8.8 | May 11, 2018 |
| CVE-2018-2738 | Vulnerability in the Oracle Retail Central Office component of Oracle Retail Applications (subcomponent: Security). Supported versions that are affected are 13… | MEDIUM | 6.5 | Apr 19, 2018 |
| CVE-2018-1272 | spring-framework: Multipart content pollution | HIGH | 7.5 | Apr 6, 2018 |
| CVE-2018-1271 | spring-framework: Directory traversal vulnerability with static resources on Windows filesystems | MEDIUM | 5.9 | Apr 6, 2018 |
| CVE-2018-1270 | spring-framework: Possible RCE via spring messaging | CRITICAL | 9.8 | Apr 6, 2018 |
| CVE-2017-12617 KEV | tomcat: Remote Code Execution bypass for CVE-2017-12615 | HIGH | 8.1 | Oct 3, 2017 |
Showing 1 to 20 of 20 CVEs