Oracle
Oracle Banking Trade Finance Process Management: vulnerabilidades y CVE
Oracle Banking Trade Finance Process Management tiene 15 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 3 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses1
Críticas3
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22963 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-61097 | Crítica (9.6) | 0.19% | — | 21 jul 2026 | Vulnerability in the Oracle Banking Trade Finance Process Management product of Oracle Financial Services Applications (component: Common). Supported versions that are affected are 14.6.0-14.8.0. Easily exploitable… |
| CVE-2022-21474 | Media (5.9) | 0.63% | — | 19 abr 2022 | Vulnerability in the Oracle Banking Trade Finance product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows… |
| CVE-2022-22963 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in… |
| CVE-2021-41973 | Media (6.5) | 4.6% | — | 1 nov 2021 | In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is… |
| CVE-2021-29505 | Alta (8.8) | 77% | — | 28 may 2021 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by… |
| CVE-2021-21409 | Media (5.9) | 4.9% | — | 30 mar 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version… |
| CVE-2021-27906 | Media (5.5) | 3.3% | — | 19 mar 2021 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
| CVE-2021-27807 | Media (5.5) | 3.0% | — | 19 mar 2021 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
| CVE-2021-23337 | Alta (7.2) | 21% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
| CVE-2020-28500 | Media (5.3) | 7.3% | — | 15 feb 2021 | Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. |
| CVE-2021-21290 | Media (5.5) | 1.8% | — | 8 feb 2021 | Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty before version 4.1.59.Final there is a… |
| CVE-2020-26217 | Alta (8.8) | 85% | — | 16 nov 2020 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on… |
| CVE-2020-8203 | Alta (7.4) | 5.2% | — | 15 jul 2020 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. |
| CVE-2019-12399 | Alta (7.5) | 3.9% | — | 14 ene 2020 | When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized… |
| CVE-2019-0228 | Crítica (9.8) | 9.5% | — | 17 abr 2019 | Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted XFDF. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.