Oracle Data Integrator vulnerabilities
36 known vulnerabilities affecting oracle/data_integrator.
Total CVEs
36
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH16MEDIUM8LOW4
Vulnerabilities
Page 2 of 2
CVE-2020-9488LOWCVSS 3.7v12.2.1.3.0v12.2.1.4.02020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2019-10219MEDIUMCVSS 6.1v12.2.1.3.0v12.2.1.4.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-2943MEDIUMCVSS 6.5v12.2.1.3.02019-10-16
CVE-2019-2943 [MEDIUM] CVE-2019-2943: Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio).
Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Studio). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized access
nvd
CVE-2019-17195CRITICALCVSS 9.8v12.2.1.4.02019-10-15
CVE-2019-17195 [CRITICAL] CWE-755 CVE-2019-17195: Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, wh
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
nvd
CVE-2019-17359HIGHCVSS 7.5v12.2.1.4.02019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all
The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2019-2720LOWCVSS 3.1v11.1.1.9.0v12.2.1.3.02019-04-23
CVE-2019-2720 [LOW] CVE-2019-2720: Vulnerability in the Oracle Data Integrator component of Oracle Fusion Middleware (subcomponent: ODI
Vulnerability in the Oracle Data Integrator component of Oracle Fusion Middleware (subcomponent: ODI Tools). Supported versions that are affected are 11.1.1.9.0 and 12.2.1.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in
nvd
CVE-2019-10247MEDIUMCVSS 5.3v12.2.1.3.0v12.2.1.4.02019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser
In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2019-10246MEDIUMCVSS 5.3v12.2.1.3.0v12.2.1.4.02019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to
In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2018-1000613CRITICALCVSS 9.8v12.2.1.3.02018-07-09
CVE-2018-1000613 [CRITICAL] CWE-470 CVE-2018-1000613: Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not in
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT private key deserialization that can result in Deserializing an XMSS/XMSS^MT private key can result
nvd
CVE-2018-8013CRITICALCVSS 9.8v12.2.1.3.02018-05-24
CVE-2018-8013 [CRITICAL] CWE-502 CVE-2018-8013: In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes
In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was to check the class type before calling newInstance in deserialization.
nvd
CVE-2018-9019CRITICALCVSS 9.8v11.1.1.9.0v12.2.1.3.0+1 more2018-05-22
CVE-2018-9019 [CRITICAL] CWE-89 CVE-2018-9019: SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbi
SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.
nvd
CVE-2018-7318CRITICALCVSS 9.8PoCv11.1.1.9.0v12.2.1.3.0+1 more2018-02-22
CVE-2018-7318 [CRITICAL] CWE-89 CVE-2018-7318: SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search,
SQL Injection exists in the CheckList 1.1.1 component for Joomla! via the title_search, tag_search, name_search, description_search, or filter_order parameter.
nvd
CVE-2015-8965CRITICALCVSS 9.8v12.2.1.3.0v12.2.1.4.02017-04-06
CVE-2015-8965 [CRITICAL] CWE-264 CVE-2015-8965: Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbi
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController servlet in jviews-framework-all.jar does not require explicit configuration of servlets that can b
nvd
CVE-2017-5611CRITICALCVSS 9.8v11.1.1.9.0v12.2.1.3.0+1 more2017-01-30
CVE-2017-5611 [CRITICAL] CWE-89 CVE-2017-5611: SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2
SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name.
nvd
CVE-2016-5602MEDIUMCVSS 5.7v11.1.1.7.0v11.1.1.9.0+3 more2016-10-25
CVE-2016-5602 [MEDIUM] CWE-200 CVE-2016-5602: Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Code Generation Engine.
nvd
CVE-2016-5618LOWCVSS 3.1v11.1.1.7.0v11.1.1.9.0+4 more2016-10-25
CVE-2016-5618 [LOW] CWE-200 CVE-2016-5618: Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1
Unspecified vulnerability in the Oracle Data Integrator component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 12.1.2.0.0, 12.1.3.0.0, 12.2.1.0.0, and 12.2.1.1.0 allows remote authenticated users to affect confidentiality via vectors related to Code Generation Engine.
nvd
← Previous2 / 2