cbcvebase.

Oracle Business Process Management Suite vulnerabilities

31 known vulnerabilities affecting oracle/business_process_management_suite.

Total CVEs
31
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL10HIGH13MEDIUM8

Vulnerabilities

Page 2 of 2
CVE-2021-35517P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02021-07-13
CVE-2021-35517 [HIGH] CWE-130 CVE-2021-35517: When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memo When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
nvd
CVE-2019-2706P3HIGHCVSS 8.2v11.1.1.9.02019-04-23
CVE-2019-2706 [HIGH] CVE-2019-2706: Vulnerability in the Oracle Business Process Management Suite component of Oracle Fusion Middleware Vulnerability in the Oracle Business Process Management Suite component of Oracle Fusion Middleware (subcomponent: BPM Foundation Services). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. Successful attacks
nvd
CVE-2018-11761P3HIGHCVSS 7.5v12.1.3.0.0v12.2.1.3.02018-09-19
CVE-2018-11761 [HIGH] CWE-611 CVE-2018-11761: In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vulnerability which can lead to a denial of service attack.
nvd
CVE-2019-17359P3HIGHCVSS 7.5v12.2.1.3.0v12.2.1.4.02019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2018-1000180P3HIGHCVSS 7.5v11.1.1.9.0v12.1.3.0.0+1 more2018-06-05
CVE-2018-1000180 [HIGH] CWE-327 CVE-2018-1000180: Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level in Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. This appears to be fixed in versions BC 1.60 beta 4 and later, BC-FJA 1.0.2 and later.
nvd
CVE-2020-1945P4MEDIUMCVSS 6.3v12.2.1.3.0v12.2.1.4.02020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2026-34284P4MEDIUMCVSS 6.1v12.2.1.4.0v14.1.2.0.02026-04-21
CVE-2026-34284 [MEDIUM] CWE-284 CVE-2026-34284: Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (c Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human workflow 11g+). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite. S
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2020-17521P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
CVE-2020-1950P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02020-03-23
CVE-2020-1950 [MEDIUM] CWE-400 CVE-2020-1950: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2020-1951P4MEDIUMCVSS 5.5v12.2.1.3.0v12.2.1.4.02020-03-23
CVE-2020-1951 [MEDIUM] CWE-835 CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in ver A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
Oracle Business Process Management Suite vulnerabilities | cvebase