Oracle
Oracle Financial Services Analytical Applications Infrastructure: vulnerabilidades y CVE
Oracle Financial Services Analytical Applications Infrastructure tiene 90 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 18 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE90
Últimos 12 meses12
Críticas18
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-22963 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in… |
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
| CVE-2017-12617 | Alta (8.1) | 100% | ⚠ Explotación activa | 4 oct 2017 | When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34325 | Media (6.8) | 0.14% | — | 21 abr 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9,… |
| CVE-2026-34321 | Media (4.8) | 0.25% | — | 21 abr 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9,… |
| CVE-2026-34314 | Media (6.8) | 0.29% | — | 21 abr 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2026-34313 | Media (6.5) | 0.39% | — | 21 abr 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2026-34310 | Alta (7.5) | 0.41% | — | 21 abr 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2026-22010 | Alta (7.5) | 0.31% | — | 21 abr 2026 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2025-61756 | Alta (7.5) | 0.32% | — | 21 oct 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are… |
| CVE-2025-61751 | Alta (8.1) | 0.33% | — | 21 oct 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2025-53037 | Crítica (9.8) | 0.47% | — | 21 oct 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2025-53036 | Alta (8.6) | 0.41% | — | 21 oct 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2025-53035 | Media (6.5) | 0.33% | — | 21 oct 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2025-53034 | Media (5.4) | 0.24% | — | 21 oct 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7… |
| CVE-2025-53031 | Media (5.3) | 0.29% | — | 15 jul 2025 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.8, 8.0.8.5,… |
| CVE-2023-21901 | Alta (7.4) | 0.32% | — | 16 ene 2024 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8,… |
| CVE-2022-22965 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the… |
| CVE-2022-22963 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 abr 2022 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in… |
| CVE-2022-24729 | Alta (7.5) | 2.5% | — | 16 mar 2022 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular… |
| CVE-2022-24728 | Media (5.4) | 1.2% | — | 16 mar 2022 | CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The… |
| CVE-2020-36518 | Alta (7.5) | 4.9% | — | 11 mar 2022 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
| CVE-2022-23437 | Media (6.5) | 12% | — | 24 ene 2022 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes… |
| CVE-2021-35687 | Media (5.3) | 1.1% | — | 19 ene 2022 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are… |
| CVE-2021-35686 | Media (4.3) | 0.69% | — | 19 ene 2022 | Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are… |
| CVE-2021-45105 | Media (5.9) | 100% | — | 18 dic 2021 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data… |
| CVE-2021-38153 | Media (5.9) | 6.3% | — | 22 sept 2021 | Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should… |
| CVE-2021-37695 | Media (5.4) | 1.3% | — | 13 ago 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The… |
| CVE-2021-32809 | Media (5.4) | 1.2% | — | 12 ago 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability… |
| CVE-2021-32808 | Media (5.4) | 1.2% | — | 12 ago 2021 | ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse… |
| CVE-2021-2351 | Alta (7.5) | 2.4% | — | 21 jul 2021 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated… |
| CVE-2021-36374 | Media (5.5) | 2.6% | — | 14 jul 2021 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to… |
| CVE-2021-36373 | Media (5.5) | 2.5% | — | 14 jul 2021 | When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.