Oracle
Oracle Banking Virtual Account Management: vulnerabilidades y CVE
Oracle Banking Virtual Account Management tiene 39 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 10 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE39
Últimos 12 meses0
Críticas10
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22963 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-21908 | Media (6) | 0.43% | — | 18 abr 2023 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7.… |
| CVE-2023-21907 | Media (6) | 0.43% | — | 18 abr 2023 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7.… |
| CVE-2023-21906 | Media (6.1) | 0.58% | — | 18 abr 2023 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: SMS Module). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable… |
| CVE-2023-21905 | Media (6.1) | 0.55% | — | 18 abr 2023 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable… |
| CVE-2023-21904 | Media (5.3) | 0.40% | — | 18 abr 2023 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7.… |
| CVE-2023-21903 | Media (5.3) | 0.40% | — | 18 abr 2023 | Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Internal Tfr Domain). Supported versions that are affected are 14.5, 14.6 and 14.7.… |
| CVE-2022-22963 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in… |
| CVE-2021-21351 | Crítica (9.1) | 82% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by… |
| CVE-2021-21350 | Crítica (9.8) | 15% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the… |
| CVE-2021-21349 | Alta (8.6) | 47% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not… |
| CVE-2021-21348 | Alta (7.5) | 14% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and… |
| CVE-2021-21347 | Crítica (9.8) | 14% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21346 | Crítica (9.8) | 76% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21345 | Crítica (9.9) | 72% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the… |
| CVE-2021-21344 | Crítica (9.8) | 76% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21343 | Alta (7.5) | 47% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the… |
| CVE-2021-21342 | Crítica (9.1) | 50% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the… |
| CVE-2021-27906 | Media (5.5) | 3.3% | — | 19 mar 2021 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
| CVE-2021-27807 | Media (5.5) | 3.0% | — | 19 mar 2021 | A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
| CVE-2020-36183 | Alta (8.1) | 5.0% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool. |
| CVE-2020-36182 | Alta (8.1) | 4.1% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS. |
| CVE-2020-36180 | Alta (8.1) | 4.1% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. |
| CVE-2020-36179 | Alta (8.1) | 17% | — | 7 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS. |
| CVE-2020-36189 | Alta (8.1) | 4.0% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource. |
| CVE-2020-36188 | Alta (8.1) | 8.8% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource. |
| CVE-2020-36187 | Alta (8.1) | 4.2% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource. |
| CVE-2020-36186 | Alta (8.1) | 4.2% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource. |
| CVE-2020-36185 | Alta (8.1) | 4.2% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource. |
| CVE-2020-36184 | Alta (8.1) | 8.4% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. |
| CVE-2020-36181 | Alta (8.1) | 4.1% | — | 6 ene 2021 | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.