cbcvebase.

Oracle Financial Services Analytical Applications Infrastructure vulnerabilities

90 known vulnerabilities affecting oracle/financial_services_analytical_applications_infrastructure.

Total CVEs
90
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL18HIGH30MEDIUM41LOW1

Vulnerabilities

Page 3 of 5
CVE-2019-12399P3HIGHCVSS 7.5≥ 8.0.6, ≤ 8.1.02020-01-14
CVE-2019-12399 [HIGH] CWE-319 CVE-2019-12399: When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configur When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect c
nvd
CVE-2019-17359P3HIGHCVSS 7.5≥ 8.0.6, ≤ 8.0.92019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2020-11112P3HIGHCVSS 8.8≥ 8.0.6, ≤ 8.1.02020-03-31
CVE-2020-11112 [HIGH] CWE-502 CVE-2020-11112: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
nvd
CVE-2020-10672P3HIGHCVSS 8.8≥ 8.0.6, ≤ 8.1.02020-03-18
CVE-2020-10672 [HIGH] CWE-502 CVE-2020-10672: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
nvd
CVE-2021-22118P3HIGHCVSS 7.8≥ 8.0.8, ≤ 8.1.12021-05-27
CVE-2021-22118 [HIGH] CWE-269 CVE-2021-22118: In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux app In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with mult
nvd
CVE-2020-10968P3HIGHCVSS 8.8≥ 8.0.6, ≤ 8.1.02020-03-26
CVE-2020-10968 [HIGH] CWE-502 CVE-2020-10968: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
nvd
CVE-2022-24729P3HIGHCVSS 7.5≥ 8.0.7.0.0, ≤ 8.1.0.0.0v8.1.1.0+2 more2022-03-16
CVE-2022-24729 [HIGH] CWE-400 CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.1 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0.
nvd
CVE-2020-5421P3MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.1.02020-09-19
CVE-2020-5421 [MEDIUM] CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and olde In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
nvd
CVE-2023-21901P3HIGHCVSS 7.4v8.0.7v8.0.8+4 more2024-01-16
CVE-2023-21901 [HIGH] CWE-284 CVE-2023-21901: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.7, 8.0.8, 8.0.9, 8.1.0, 8.1.1 and 8.1.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compro
nvd
CVE-2026-34314P3MEDIUMCVSS 6.8v8.0.7.9.0v8.0.8.7.0+1 more2026-04-21
CVE-2026-34314 [MEDIUM] CWE-284 CVE-2026-34314: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Finan
nvd
CVE-2025-53035P3MEDIUMCVSS 6.5v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-53035 [MEDIUM] CWE-284 CVE-2025-53035: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi
nvd
CVE-2026-34313P3MEDIUMCVSS 6.5v8.0.7.9.0v8.0.8.7.0+1 more2026-04-21
CVE-2026-34313 [MEDIUM] CWE-200 CVE-2026-34313: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financi
nvd
CVE-2018-2660P3HIGHCVSS 7.4v7.3.5.0.0v7.3.5.1.0+8 more2018-01-18
CVE-2018-2660 [HIGH] CVE-2018-2660: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of O Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 7.3.5.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytical
nvd
CVE-2020-36518P3HIGHCVSS 7.5≥ 8.0.7, ≤ 8.1.0.0v8.1.1.0+2 more2022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2020-2688P3HIGHCVSS 7.1≥ 8.0.4, ≤ 8.0.82020-01-15
CVE-2020-2688 [HIGH] CVE-2020-2688: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Object Migration). Supported versions that are affected are 8.0.4-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytica
nvd
CVE-2020-14602P3HIGHCVSS 7.1≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14602 [HIGH] CVE-2020-14602: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytica
nvd
CVE-2020-2793P3HIGHCVSS 7.1≥ 8.0.6.0.0, ≤ 8.0.9.0.02020-04-15
CVE-2020-2793 [HIGH] CVE-2020-2793: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6 - 8.0.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analytica
nvd
CVE-2022-23437P3MEDIUMCVSS 6.5≥ 8.0.6.0.0, ≤ 8.0.9.0≥ 8.1.0.0, < 8.1.2.02022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2020-14685P3MEDIUMCVSS 6.5≥ 8.0.6.0.0, ≤ 8.1.0.0.02020-07-15
CVE-2020-14685 [MEDIUM] CVE-2020-14685: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd
CVE-2020-14605P3MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14605 [MEDIUM] CVE-2020-14605: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd