Oracle
Oracle Banking Enterprise Default Management: vulnerabilities and CVEs
Oracle Banking Enterprise Default Management has 23 published vulnerabilities, 0 of them in the last 12 months. 7 are rated critical and 0 are listed by CISA as actively exploited.
CVEs23
Last 12 months0
Critical7
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-45105 | Medium (5.9) | 100% | — | Dec 18, 2021 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data… |
| CVE-2021-2351 | High (7.5) | 2.4% | — | Jul 21, 2021 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated… |
| CVE-2021-35043 | Medium (6.1) | 1.5% | — | Jul 19, 2021 | OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character. |
| CVE-2021-36090 | High (7.5) | 13% | — | Jul 13, 2021 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of… |
| CVE-2021-35517 | High (7.5) | 11% | — | Jul 13, 2021 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of… |
| CVE-2021-35516 | High (7.5) | 12% | — | Jul 13, 2021 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of… |
| CVE-2021-35515 | High (7.5) | 12% | — | Jul 13, 2021 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that… |
| CVE-2020-6950 | Medium (6.5) | 10% | — | Jun 2, 2021 | Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. |
| CVE-2021-29425 | Medium (4.8) | 9.9% | — | Apr 13, 2021 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to… |
| CVE-2021-21351 | Critical (9.1) | 82% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by… |
| CVE-2021-21350 | Critical (9.8) | 15% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the… |
| CVE-2021-21349 | High (8.6) | 47% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not… |
| CVE-2021-21348 | High (7.5) | 14% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and… |
| CVE-2021-21347 | Critical (9.8) | 14% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21346 | Critical (9.8) | 76% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21345 | Critical (9.9) | 72% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the… |
| CVE-2021-21344 | Critical (9.8) | 76% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21343 | High (7.5) | 47% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the… |
| CVE-2021-21342 | Critical (9.1) | 50% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the… |
| CVE-2021-21341 | High (7.5) | 78% | — | Mar 23, 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending… |
| CVE-2020-13936 | High (8.8) | 23% | — | Mar 10, 2021 | An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications… |
| CVE-2020-9281 | Medium (6.1) | 4.3% | — | Mar 7, 2020 | A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected… |
| CVE-2019-10219 | Medium (6.1) | 2.2% | — | Nov 8, 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can… |