CVE-2011-0818
published 2011-04-20CVE-2011-0818: Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect…
PriorityP421medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
1.16%
63.6th percentile
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | enterpriseone_tools | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone | — | — |
| oracle | jd_edwards_enterpriseone_ep | — | — |
| oracle | oneworld_tools | <= 24.1.3 | — |
| oracle | peoplesoft_and_jdedwards_product_suite | — | — |
| oracle | peoplesoft_and_jdedwards_product_suite | — | — |
| oracle | peoplesoft_and_jdedwards_suite_scm | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
ghsa5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mff3-87fp-5r9j: Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8
ghsa_unreviewed·2022-05-17
CVE-2011-0818 [MEDIUM] GHSA-mff3-87fp-5r9j: Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8
Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect availability, related to Enterprise Infrastructure SEC.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
ghsa·2022-05-17·CVSS 5.0
CVE-2011-5245 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
Exposure of Sensitive Information to an Unauthorized Actor in RESTEasy
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
Red Hat
RESTEasy: XML eXternal Entity (XXE) flaw
vendor_redhat·2011-12-30·CVSS 5.0
CVE-2011-5245 [MEDIUM] CWE-611 RESTEasy: XML eXternal Entity (XXE) flaw
RESTEasy: XML eXternal Entity (XXE) flaw
The readFrom function in providers.jaxb.JAXBXmlTypeProvider in RESTEasy before 2.3.2 allows remote attackers to read arbitrary files via an external entity reference in a Java Architecture for XML Binding (JAXB) input, aka an XML external entity (XXE) injection attack, a similar vulnerability to CVE-2012-0818.
Package: Security (Red Hat JBoss BRMS 5) - Affected
Package: Teiid (Red Hat JBoss Data Virtualization 6) - Affected
Package: Security (Red Hat JBoss SOA Platform 5) - Affected
Package: resteasy (Red Hat Storage 2.1) - Affected
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2011-04-20
Published