Oracle Agile Engineering Data Management vulnerabilities
30 known vulnerabilities affecting oracle/agile_engineering_data_management.
Total CVEs
30
CISA KEV
2
actively exploited
Public exploits
7
Exploited in wild
3
Severity breakdown
CRITICAL3HIGH12MEDIUM12LOW3
Vulnerabilities
Page 2 of 2
CVE-2020-1935P4MEDIUMCVSS 4.8v6.2.1.02020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8v6.2.1.02020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v6.2.1.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2020-17521P4MEDIUMCVSS 5.5v6.2.1.02020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
CVE-2021-36374P4MEDIUMCVSS 5.5v6.2.1.02021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2017-10161P4MEDIUMCVSS 4.8v6.1.3.0v6.2.2.02017-10-19
CVE-2017-10161 [MEDIUM] CVE-2017-10161: Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Su
Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Engineering Data Management. Successf
nvd
CVE-2016-0497P4MEDIUMCVSS 4.3v6.1.2.2v6.1.3.0+1 more2016-01-21
CVE-2016-0497 [MEDIUM] CVE-2016-0497: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows remote attackers to affect integrity via unknown vectors related to Web Client.
nvd
CVE-2016-3428P4LOWCVSS 3.1v6.1.3.0v6.2.0.02016-04-21
CVE-2016-3428 [LOW] CVE-2016-3428: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface.
nvd
CVE-2021-1996P4LOWCVSS 2.4v6.2.1.02021-01-20
CVE-2021-1996 [LOW] CVE-2021-1996: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Serv
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a perso
nvd
CVE-2016-0498P4LOWCVSS 1.5v6.1.2.2v6.1.3.0+1 more2016-01-21
CVE-2016-0498 [LOW] CVE-2016-0498: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply
Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install.
nvd
← Previous2 / 2