cbcvebase.

Oracle Banking Payments vulnerabilities

35 known vulnerabilities affecting oracle/banking_payments.

Total CVEs
35
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH10MEDIUM24

Vulnerabilities

Page 2 of 2
CVE-2021-41973P4MEDIUMCVSS 6.5v14.52021-11-01
CVE-2021-41973 [MEDIUM] CWE-835 CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
nvd
CVE-2018-3025P4MEDIUMCVSS 5.3v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3025 [MEDIUM] CVE-2018-3025: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful atta
nvd
CVE-2018-2896P4MEDIUMCVSS 6.1v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-2896 [MEDIUM] CVE-2018-2896: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attac
nvd
CVE-2018-3024P4MEDIUMCVSS 5.4v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3024 [MEDIUM] CVE-2018-3024: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attack
nvd
CVE-2018-2748P4MEDIUMCVSS 6.1v12.3.0v12.4.0+2 more2018-04-19
CVE-2018-2748 [MEDIUM] CVE-2018-2748: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successf
nvd
CVE-2022-21475P4MEDIUMCVSS 5.9v14.52022-04-19
CVE-2022-21475 [MEDIUM] CVE-2022-21475: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks require human interaction from a p
nvd
CVE-2018-3023P4MEDIUMCVSS 5.4v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3023 [MEDIUM] CVE-2018-3023: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attack
nvd
CVE-2018-2708P4MEDIUMCVSS 5.3v12.3.0v12.4.02018-01-18
CVE-2018-2708 [MEDIUM] CVE-2018-2708: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerabilit
nvd
CVE-2020-2710P4MEDIUMCVSS 5.4≥ 14.1.0, ≤ 14.3.02020-01-15
CVE-2020-2710 [MEDIUM] CVE-2020-2710: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unau
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5v14.0.0v14.1.02019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2018-3026P4MEDIUMCVSS 5.4v12.2.0v12.3.0+3 more2018-07-18
CVE-2018-3026 [MEDIUM] CVE-2018-3026: Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (su Vulnerability in the Oracle Banking Payments component of Oracle Financial Services Applications (subcomponent: Payments Core). Supported versions that are affected are 12.2.0, 12.3.0, 12.4.0, 12.5.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attack
nvd
CVE-2018-2749P4MEDIUMCVSS 5.4v12.3.0v12.4.0+2 more2018-04-19
CVE-2018-2749 [MEDIUM] CVE-2018-2749: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2020-2712P4MEDIUMCVSS 5.4≥ 14.1.0, ≤ 14.3.02020-01-15
CVE-2020-2712 [MEDIUM] CVE-2020-2712: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks require human interaction from a person
nvd
CVE-2023-21915P4MEDIUMCVSS 4.6v14.5v14.6+1 more2023-04-18
CVE-2023-21915 [MEDIUM] CVE-2023-21915: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Book/Internal Transfer). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks require human
nvd
CVE-2020-2714P4MEDIUMCVSS 4.3≥ 14.1.0, ≤ 14.3.02020-01-15
CVE-2020-2714 [MEDIUM] CVE-2020-2714: Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (comp Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core). Supported versions that are affected are 14.1.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments. Successful attacks of this vulnerability can result in unau
nvd
Oracle Banking Payments vulnerabilities | cvebase