Oracle / Siebel UI Framework
53 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-21909 | Vulnerability in the Siebel CRM product of Oracle Siebel CRM (component: UI Framework). Supported versions that are affected are 23.3 and prior. Easily exploit… | MEDIUM | 6.5 | Apr 18, 2023 |
| CVE-2021-44832 | Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration | MEDIUM | 6.6 | Dec 28, 2021 |
| CVE-2021-45105 | Apache Log4j2 does not always protect from infinite recursion in lookup evaluation | HIGH | 8.6 | Dec 18, 2021 |
| CVE-2021-32808 | Cross-site scripting in ckeditor via abuse of undo functionality | HIGH | 7.6 | Aug 12, 2021 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Diffi… | HIGH | 8.3 | Jul 20, 2021 |
| CVE-2021-25329 | Incomplete fix for CVE-2020-9484 | HIGH | 7.0 | Mar 1, 2021 |
| CVE-2021-25122 | Apache Tomcat h2c request mix-up | HIGH | 7.5 | Mar 1, 2021 |
| CVE-2021-26272 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then pr… | MEDIUM | 6.5 | Jan 26, 2021 |
| CVE-2021-26271 | It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dia… | MEDIUM | 6.5 | Jan 26, 2021 |
| CVE-2021-1996 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0… | LOW | 2.4 | Jan 20, 2021 |
| CVE-2020-24750 | jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration | HIGH | 8.1 | Sep 17, 2020 |
| CVE-2020-24616 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource | HIGH | 8.1 | Aug 25, 2020 |
| CVE-2020-14531 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 20.6 and prior. Diffic… | MEDIUM | 5.9 | Jul 15, 2020 |
| CVE-2020-13935 | tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-13934 | tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-11996 | tomcat: specially crafted sequence of HTTP/2 requests can lead to DoS | HIGH | 7.5 | Jun 26, 2020 |
| CVE-2020-9484 | tomcat: deserialization flaw in session persistence storage leading to RCE | HIGH | 7.0 | May 20, 2020 |
| CVE-2020-11022 | jQuery has a potential XSS vulnerability | MEDIUM | 6.9 | Apr 29, 2020 |
| CVE-2020-9488 | log4j: improper validation of certificate with host mismatch in SMTP appender | LOW | 3.7 | Apr 27, 2020 |
| CVE-2020-2738 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI, SWSE). Supported versions that are affected are 20.2 and prior. Easily e… | MEDIUM | 4.3 | Apr 15, 2020 |
| CVE-2020-1938 KEV | tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability | CRITICAL | 9.8 | Feb 24, 2020 |
| CVE-2020-1935 | tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2020-2564 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.10 and prior. Easily exploi… | MEDIUM | 5.3 | Jan 15, 2020 |
| CVE-2020-2560 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: SWSE Server). Supported versions that are affected are 19.10 and prior. Easil… | MEDIUM | 4.7 | Jan 15, 2020 |
| CVE-2020-2559 | Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: UIF Open UI). Supported versions that are affected are 19.7 and prior. Easily… | MEDIUM | 5.3 | Jan 15, 2020 |
Showing 1 to 25 of 53 CVEs