cbcvebase.

Oracle Banking Payments vulnerabilities

35 known vulnerabilities affecting oracle/banking_payments.

Total CVEs
35
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH10MEDIUM24

Vulnerabilities

Page 1 of 2
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev14.52021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2019-13990P3CRITICALCVSS 9.8≥ 14.1.0, ≤ 14.4.02019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3 initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd
CVE-2018-2705P3HIGHCVSS 8.8v12.3.0v12.4.02018-01-18
CVE-2018-2705 [HIGH] CVE-2018-2705: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability ca
nvd
CVE-2018-3027P3HIGHCVSS 8.1v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3027 [HIGH] CVE-2018-3027: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks
nvd
CVE-2019-12402P3HIGHCVSS 7.5≥ 14.1.0, ≤ 14.4.02019-08-30
CVE-2019-12402 [HIGH] CWE-835 CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get int The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
nvd
CVE-2021-35515P3HIGHCVSS 7.5v14.52021-07-13
CVE-2021-35515 [HIGH] CWE-834 CVE-2021-35515: When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2018-2704P3HIGHCVSS 8.1v12.3.0v12.4.02018-01-18
CVE-2018-2704 [HIGH] CVE-2018-2704: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability ca
nvd
CVE-2021-36090P3HIGHCVSS 7.5v14.52021-07-13
CVE-2021-36090 [HIGH] CWE-130 CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memo When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
nvd
CVE-2021-35517P3HIGHCVSS 7.5v14.52021-07-13
CVE-2021-35517 [HIGH] CWE-130 CVE-2021-35517: When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memo When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
nvd
CVE-2019-12399P3HIGHCVSS 7.5v14.4.02020-01-14
CVE-2019-12399 [HIGH] CWE-319 CVE-2019-12399: When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configur When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect c
nvd
CVE-2018-2746P3HIGHCVSS 7.1v12.3.0v12.4.0+2 more2018-04-19
CVE-2018-2746 [HIGH] CVE-2018-2746: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful
nvd
CVE-2018-2747P3MEDIUMCVSS 6.5v12.3.0v12.4.0+2 more2018-04-19
CVE-2018-2747 [MEDIUM] CVE-2018-2747: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2020-14896P3MEDIUMCVSS 6.5≥ 14.1.0, ≤ 14.4.02020-10-21
CVE-2020-14896 [MEDIUM] CVE-2020-14896: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in un
nvd
CVE-2020-2713P3HIGHCVSS 7.1≥ 14.1.0, ≤ 14.3.02020-01-15
CVE-2020-2713 [HIGH] CVE-2020-2713: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2020-2711P3MEDIUMCVSS 6.5≥ 14.1.0, ≤ 14.3.02020-01-15
CVE-2020-2711 [MEDIUM] CVE-2020-2711: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unau
nvd
CVE-2018-3020P3MEDIUMCVSS 6.3v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3020 [MEDIUM] CVE-2018-3020: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attack
nvd
CVE-2021-30129P3MEDIUMCVSS 6.5v14.52021-07-12
CVE-2021-30129 [MEDIUM] CWE-772 CVE-2021-30129: A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing a A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
nvd
CVE-2018-3022P3MEDIUMCVSS 6.5v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3022 [MEDIUM] CVE-2018-3022: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attack
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9≥ 14.1.0, ≤ 14.4.02018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2018-3021P4MEDIUMCVSS 5.3v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3021 [MEDIUM] CVE-2018-3021: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attac
nvd
Oracle Banking Payments vulnerabilities | cvebase