Oracle Financial Services Analytical Applications Infrastructure vulnerabilities
84 known vulnerabilities affecting oracle/financial_services_analytical_applications_infrastructure.
Total CVEs
84
CISA KEV
3
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL18HIGH28MEDIUM37LOW1
Vulnerabilities
Page 1 of 5
CVE-2025-53037CRITICALCVSS 9.8v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-53037 [CRITICAL] CWE-306 CVE-2025-53037: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fina
nvd
CVE-2025-53036HIGHCVSS 8.6v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-53036 [HIGH] CWE-200 CVE-2025-53036: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financia
nvd
CVE-2025-61756HIGHCVSS 7.5v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-61756 [HIGH] CWE-306 CVE-2025-61756: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: System Configuration). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Ora
nvd
CVE-2025-61751HIGHCVSS 8.1v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-61751 [HIGH] CWE-862 CVE-2025-61751: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial
nvd
CVE-2025-53035MEDIUMCVSS 6.5v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-53035 [MEDIUM] CWE-284 CVE-2025-53035: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi
nvd
CVE-2025-53034MEDIUMCVSS 5.4v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-53034 [MEDIUM] CWE-306 CVE-2025-53034: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financ
nvd
CVE-2025-53031MEDIUMCVSS 5.3v8.0.7.8v8.0.8.5+3 more2025-07-15
CVE-2025-53031 [MEDIUM] CWE-497 CVE-2025-53031: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.8, 8.0.8.5, 8.0.8.6, 8.1.1.4 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compro
nvd
CVE-2023-21901HIGHCVSS 7.4v8.0.7v8.0.8+4 more2024-01-16
CVE-2023-21901 [HIGH] CWE-284 CVE-2023-21901: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compro
nvd
CVE-2022-22965CRITICALCVSS 9.8KEVPoCv8.1.1v8.1.2.02022-04-01
CVE-2022-22965 [CRITICAL] CWE-94 CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execut
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature
nvd
CVE-2022-22963CRITICALCVSS 9.8KEVPoCv8.1.1.0v8.1.2.02022-04-01
CVE-2022-22963 [CRITICAL] CWE-94 CVE-2022-22963: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing fu
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
nvd
CVE-2022-24729HIGHCVSS 7.5≥ 8.0.7.0.0, ≤ 8.1.0.0.0v8.1.1.0+2 more2022-03-16
CVE-2022-24729 [MEDIUM] CWE-400 CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.1
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.
nvd
CVE-2022-24728MEDIUMCVSS 5.4≥ 8.0.7.0.0, ≤ 8.1.0.0.0v8.1.1.0+2 more2022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been disco
CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. T
nvd
CVE-2020-36518HIGHCVSS 7.5≥ 8.0.7, ≤ 8.1.0.0v8.1.1.0+2 more2022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2022-23437MEDIUMCVSS 6.5≥ 8.0.6.0.0, ≤ 8.0.9.0≥ 8.1.0.0, < 8.1.2.02022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2021-35687MEDIUMCVSS 5.3≥ 8.0.7, ≤ 8.1.12022-01-19
CVE-2021-35687 [MEDIUM] CVE-2021-35687: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Servi
nvd
CVE-2021-35686MEDIUMCVSS 4.3≥ 8.0.7, ≤ 8.1.12022-01-19
CVE-2021-35686 [MEDIUM] CVE-2021-35686: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Servic
nvd
CVE-2021-45105MEDIUMCVSS 5.9≥ 8.0.7, ≤ 8.1.12021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-38153MEDIUMCVSS 5.9≥ 8.0.6.0, ≤ 8.0.9.0≥ 8.1.0.0.0, ≤ 8.1.202021-09-22
CVE-2021-38153 [MEDIUM] CWE-203 CVE-2021-38153: Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerab
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0
nvd
CVE-2021-37695MEDIUMCVSS 5.4≥ 8.0.7, ≤ 8.1.1v8.0.32021-08-13
CVE-2021-37695 [HIGH] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdito
nvd
CVE-2021-32808MEDIUMCVSS 5.4≥ 8.0.7, ≤ 8.1.12021-08-12
CVE-2021-32808 [HIGH] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d
ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEditor
nvd
1 / 5Next →