Oracle Banking Enterprise Default Management vulnerabilities
23 known vulnerabilities affecting oracle/banking_enterprise_default_management.
Total CVEs
23
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH10MEDIUM6
Vulnerabilities
Page 2 of 2
CVE-2020-9281P4MEDIUMCVSS 6.1v2.6.2v2.7.0+3 more2020-03-07
CVE-2020-9281 [MEDIUM] CWE-79 CVE-2020-9281: A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 a
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v2.6.2v2.7.0+3 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2021-35043P4MEDIUMCVSS 6.1v2.6.2v2.7.0+3 more2021-07-19
CVE-2021-35043 [MEDIUM] CWE-79 CVE-2021-35043: OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XH
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
nvd
← Previous2 / 2