Vulnerabilities (CVE)

Vendor filter

Oracle Subscribe

Product filter

Banking Platform Subscribe

Filter

9 total CVE
CVE Vendors Products Updated CVSS
CVE-2017-5645 4 Apache, Netapp, Oracle and 1 more 59 Log4j, Oncommand Api Services, Oncommand Insight and 56 more 2019-06-19 7.5
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
CVE-2015-9251 2 Jquery, Oracle 40 Jquery, Agile Product Lifecycle Management For Process, Banking Platform and 37 more 2019-06-10 4.3
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
CVE-2018-14721 3 Fasterxml, Debian, Oracle 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.
CVE-2018-14720 3 Fasterxml, Debian, Oracle 11 Jackson-databind, Debian Linux, Banking Platform and 8 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.
CVE-2018-14719 3 Fasterxml, Debian, Oracle 10 Jackson-databind, Debian Linux, Banking Platform and 7 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
CVE-2018-14718 3 Fasterxml, Debian, Oracle 10 Jackson-databind, Debian Linux, Banking Platform and 7 more 2019-05-30 7.5
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.
CVE-2018-12023 3 Fasterxml, Oracle, Fedoraproject 19 Jackson-databind, Banking Platform, Communications Billing And Revenue Management and 16 more 2019-05-30 5.1
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can...
CVE-2018-3246 1 Oracle 7 Weblogic Server, Banking Platform, Business Process Management Suite and 4 more 2019-04-25 5.0
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS - Web Services). Supported versions that are affected are 12.1.3.0 and 12.2.1.3. Easily exploitable vulnerability allows unauthenticated attacker...
CVE-2016-1181 2 Apache, Oracle 3 Struts, Portal, Banking Platform 2019-04-23 6.8
ActionServlet.java in Apache Struts 1 1.x through 1.3.10 mishandles multithreaded access to an ActionForm instance, which allows remote attackers to execute arbitrary code or cause a denial of service (unexpected memory access) via a multipart...