Oracle Business Activity Monitoring vulnerabilities
29 known vulnerabilities affecting oracle/business_activity_monitoring.
Total CVEs
29
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
1
Severity breakdown
CRITICAL8HIGH19MEDIUM2
Vulnerabilities
Page 2 of 2
CVE-2021-21345CRITICALCVSS 9.9PoCv11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21345 [MEDIUM] CWE-94 CVE-2021-21345: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security f
nvd
CVE-2021-21342CRITICALCVSS 9.1v11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21342 [MEDIUM] CWE-502 CVE-2021-21342: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the p
nvd
CVE-2021-21348HIGHCVSS 7.5v11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21348 [MEDIUM] CWE-400 CVE-2021-21348: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited
nvd
CVE-2021-21343HIGHCVSS 7.5v11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21343 [MEDIUM] CWE-73 CVE-2021-21343: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the formerly written objects. XStream creates therefore new instances based on these type information. An attacker can manipulate the pr
nvd
CVE-2021-21349HIGHCVSS 8.6v11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21349 [MEDIUM] CWE-502 CVE-2021-21349: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStre
nvd
CVE-2021-21341HIGHCVSS 7.5v11.1.1.9.0v12.2.1.3.0+1 more2021-03-23
CVE-2021-21341 [HIGH] CWE-400 CVE-2021-21341: XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. N
nvd
CVE-2020-26217HIGHCVSS 8.8PoCv11.1.1.9.0v12.2.1.3.0+1 more2020-11-16
CVE-2020-26217 [HIGH] CWE-78 CVE-2020-26217: XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a r
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security Framework allowlist is not affected. The linked advisory provides code workaro
nvd
CVE-2019-10219MEDIUMCVSS 6.1v12.2.1.4.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-10173CRITICALCVSS 9.8v11.1.1.9.0v12.2.1.3.0+1 more2019-07-23
CVE-2019-10173 [CRITICAL] CVE-2019-10173: It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous de
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
nvd
← Previous2 / 2