Oracle Financial Services Analytical Applications Infrastructure vulnerabilities

84 known vulnerabilities affecting oracle/financial_services_analytical_applications_infrastructure.

Total CVEs
84
CISA KEV
3
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL18HIGH28MEDIUM37LOW1

Vulnerabilities

Page 2 of 5
CVE-2021-32809MEDIUMCVSS 5.4≥ 8.0.7, ≤ 8.1.12021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2021-2351HIGHCVSS 7.5≥ 8.0.7, ≤ 8.1.12021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2021-36373MEDIUMCVSS 5.5≥ 8.0.6, ≤ 8.1.12021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd
CVE-2021-36374MEDIUMCVSS 5.5≥ 8.0.6, ≤ 8.1.12021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2021-36090HIGHCVSS 7.5≥ 8.0.6, ≤ 8.1.12021-07-13
CVE-2021-36090 [HIGH] CWE-130 CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memo When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
nvd
CVE-2021-22118HIGHCVSS 7.8≥ 8.0.8, ≤ 8.1.12021-05-27
CVE-2021-22118 [HIGH] CWE-269 CVE-2021-22118: In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux app In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with mult
nvd
CVE-2021-26291CRITICALCVSS 9.1≥ 8.0.6.0.0, ≤ 8.0.9.0.0≥ 8.1.0.0.0, ≤ 8.1.2.02021-04-23
CVE-2021-26291 [CRITICAL] CWE-346 CVE-2021-26291: Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) Apache Maven will follow repositories that are defined in a dependency’s Project Object Model (pom) which may be surprising to some users, resulting in potential risk if a malicious actor takes over that repository or is able to insert themselves into a position to pretend to be that repository. Maven is changing the default behavior in 3.8.1+ to n
nvd
CVE-2021-2140MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.1.02021-04-22
CVE-2021-2140 [MEDIUM] CVE-2021-2140: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Rules Framework). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd
CVE-2021-29425MEDIUMCVSS 4.8≥ 8.0.7, ≤ 8.1.12021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2021-26272MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2021-26271MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd
CVE-2019-17566HIGHCVSS 7.5≥ 8.0.6, ≤ 8.1.02020-11-12
CVE-2019-17566 [HIGH] CWE-918 CVE-2019-17566: Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by th Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2020-27193MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2020-11-12
CVE-2020-27193 [MEDIUM] CWE-79 CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows rem A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
nvd
CVE-2020-14824HIGHCVSS 8.6≥ 8.0.6.0.0, ≤ 8.1.0.0.02020-10-21
CVE-2020-14824 [HIGH] CVE-2020-14824: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytic
nvd
CVE-2020-11979HIGHCVSS 7.5≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2020-10-01
CVE-2020-11979 [HIGH] CWE-379 CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it crea As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modifi
nvd
CVE-2020-5421MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.1.02020-09-19
CVE-2020-5421 [MEDIUM] CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and olde In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
nvd
CVE-2020-14602HIGHCVSS 7.1≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14602 [HIGH] CVE-2020-14602: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytica
nvd
CVE-2020-14603MEDIUMCVSS 5.3≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14603 [MEDIUM] CVE-2020-14603: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyt
nvd
CVE-2020-14601MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14601 [MEDIUM] CWE-79 CVE-2020-14601: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services
nvd
CVE-2020-14604MEDIUMCVSS 5.3≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14604 [MEDIUM] CVE-2020-14604: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyt
nvd