Oracle Banking Virtual Account Management vulnerabilities
39 known vulnerabilities affecting oracle/banking_virtual_account_management.
Total CVEs
39
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH21MEDIUM8
Vulnerabilities
Page 1 of 2
CVE-2023-21908MEDIUMCVSS 6.0v14.5v14.6+1 more2023-04-18
CVE-2023-21908 [MEDIUM] CVE-2023-21908: Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Manag
nvd
CVE-2023-21906MEDIUMCVSS 6.1v14.5v14.6+1 more2023-04-18
CVE-2023-21906 [MEDIUM] CVE-2023-21906: Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: SMS Module). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management. Successfu
nvd
CVE-2023-21903MEDIUMCVSS 5.3v14.5v14.6+1 more2023-04-18
CVE-2023-21903 [MEDIUM] CVE-2023-21903: Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Internal Tfr Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Mana
nvd
CVE-2023-21907MEDIUMCVSS 6.0v14.5v14.6+1 more2023-04-18
CVE-2023-21907 [MEDIUM] CVE-2023-21907: Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Manag
nvd
CVE-2023-21905MEDIUMCVSS 6.1v14.5v14.6+1 more2023-04-18
CVE-2023-21905 [MEDIUM] CWE-284 CVE-2023-21905: Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: Routing Hub). Supported versions that are affected are 14.5, 14.6 and 14.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Management.
nvd
CVE-2023-21904MEDIUMCVSS 5.3v14.5v14.6+1 more2023-04-18
CVE-2023-21904 [MEDIUM] CVE-2023-21904: Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services
Vulnerability in the Oracle Banking Virtual Account Management product of Oracle Financial Services Applications (component: OBVAM Trn Journal Domain). Supported versions that are affected are 14.5, 14.6 and 14.7. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Banking Virtual Account Manag
nvd
CVE-2022-22963CRITICALCVSS 9.8KEVPoCv14.52022-04-01
CVE-2022-22963 [CRITICAL] CWE-94 CVE-2022-22963: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing fu
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
nvd
CVE-2021-21346CRITICALCVSS 9.8v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21346 [MEDIUM] CWE-434 CVE-2021-21346: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fram
nvd
CVE-2021-21350CRITICALCVSS 9.8v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21350 [MEDIUM] CWE-434 CVE-2021-21350: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limit
nvd
CVE-2021-21344CRITICALCVSS 9.8v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21344 [MEDIUM] CWE-434 CVE-2021-21344: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fram
nvd
CVE-2021-21351CRITICALCVSS 9.1PoCv14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21351 [MEDIUM] CWE-434 CVE-2021-21351: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework
nvd
CVE-2021-21347CRITICALCVSS 9.8v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21347 [MEDIUM] CWE-434 CVE-2021-21347: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security fram
nvd
CVE-2021-21345CRITICALCVSS 9.9PoCv14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21345 [MEDIUM] CWE-94 CVE-2021-21345: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security f
nvd
CVE-2021-21342CRITICALCVSS 9.1v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21342 [MEDIUM] CWE-502 CVE-2021-21342: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the p
nvd
CVE-2021-21348HIGHCVSS 7.5v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21348 [MEDIUM] CWE-400 CVE-2021-21348: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited
nvd
CVE-2021-21343HIGHCVSS 7.5v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21343 [MEDIUM] CWE-73 CVE-2021-21343: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the pr
nvd
CVE-2021-21349HIGHCVSS 8.6v14.2.0v14.3.0+1 more2021-03-23
CVE-2021-21349 [MEDIUM] CWE-502 CVE-2021-21349: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStre
nvd
CVE-2021-27807MEDIUMCVSS 5.5v14.2.0v14.3.0+1 more2021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27906MEDIUMCVSS 5.5v14.2.0v14.3.0+1 more2021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2020-36179HIGHCVSS 8.1v14.2.0v14.3.0+1 more2021-01-07
CVE-2020-36179 [HIGH] CWE-502 CVE-2020-36179: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
nvd
1 / 2Next →