Oracle
Oracle Financial Services Crime AND Compliance Management Studio: vulnerabilidades y CVE
Oracle Financial Services Crime AND Compliance Management Studio tiene 22 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses0
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2018-1273 | Crítica (9.8) | 97% | ⚠ Explotación activa | 11 abr 2018 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22978 | Crítica (9.8) | 12% | — | 19 may 2022 | In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using… |
| CVE-2022-22976 | Media (5.3) | 2.3% | — | 19 may 2022 | Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder… |
| CVE-2022-22971 | Media (6.5) | 3.2% | — | 12 may 2022 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |
| CVE-2022-22970 | Media (5.3) | 2.0% | — | 12 may 2022 | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or… |
| CVE-2022-24823 | Media (5.5) | 1.0% | — | 6 may 2022 | Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's… |
| CVE-2022-25647 | Alta (7.5) | 12% | — | 1 may 2022 | The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
| CVE-2020-36518 | Alta (7.5) | 4.9% | — | 11 mar 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
| CVE-2021-38296 | Alta (7.5) | 1.8% | — | 10 mar 2022 | Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for… |
| CVE-2022-23181 | Alta (7) | 0.69% | — | 27 ene 2022 | The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to… |
| CVE-2022-23437 | Media (6.5) | 12% | — | 24 ene 2022 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes… |
| CVE-2021-41303 | Crítica (9.8) | 77% | — | 17 sept 2021 | Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. |
| CVE-2021-37714 | Alta (7.5) | 6.7% | — | 18 ago 2021 | jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may… |
| CVE-2021-34429 | Media (5.3) | 99% | — | 15 jul 2021 | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is… |
| CVE-2021-36090 | Alta (7.5) | 13% | — | 13 jul 2021 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of… |
| CVE-2021-35517 | Alta (7.5) | 11% | — | 13 jul 2021 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of… |
| CVE-2021-35516 | Alta (7.5) | 12% | — | 13 jul 2021 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of… |
| CVE-2021-35515 | Alta (7.5) | 12% | — | 13 jul 2021 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that… |
| CVE-2021-23337 | Alta (7.2) | 21% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
| CVE-2020-28500 | Media (5.3) | 7.3% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. |
| CVE-2020-9492 | Alta (8.8) | 4.4% | — | 26 ene 2021 | In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. |
| CVE-2020-7712 | Alta (7.2) | 3.1% | — | 30 ago 2020 | This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function. |
| CVE-2018-1273 | Crítica (9.8) | 97% | ⚠ Explotación activa | 11 abr 2018 | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.