cbcvebase.

Oracle Financial Services Analytical Applications Infrastructure vulnerabilities

90 known vulnerabilities affecting oracle/financial_services_analytical_applications_infrastructure.

Total CVEs
90
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL18HIGH30MEDIUM41LOW1

Vulnerabilities

Page 4 of 5
CVE-2020-14662P3MEDIUMCVSS 6.3≥ 8.0.6.0.0, ≤ 8.1.0.0.02020-07-15
CVE-2020-14662 [MEDIUM] CVE-2020-14662: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd
CVE-2021-29425P4MEDIUMCVSS 4.8≥ 8.0.7, ≤ 8.1.12021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1≥ 7.3.3, ≤ 7.3.5≥ 8.0.0, ≤ 8.0.82018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2020-1945P4MEDIUMCVSS 6.3≥ 8.0.6, ≤ 8.1.02020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2021-26272P4MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2021-01-26
CVE-2021-26272 [MEDIUM] CWE-829 CVE-2021-26272: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).
nvd
CVE-2021-26271P4MEDIUMCVSS 6.5≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2021-01-26
CVE-2021-26271 [MEDIUM] CWE-829 CVE-2021-26271: It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
nvd
CVE-2026-34325P4MEDIUMCVSS 6.8v8.0.7.9.0v8.0.8.7.0+1 more2026-04-21
CVE-2026-34325 [MEDIUM] CWE-284 CVE-2026-34325: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Finan
nvd
CVE-2025-53034P4MEDIUMCVSS 5.4v8.0.7.9.0v8.0.8.7.0+1 more2025-10-21
CVE-2025-53034 [MEDIUM] CWE-306 CVE-2025-53034: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financ
nvd
CVE-2025-53031P4MEDIUMCVSS 5.3v8.0.7.8v8.0.8.5+3 more2025-07-15
CVE-2025-53031 [MEDIUM] CWE-497 CVE-2025-53031: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.8, 8.0.8.5, 8.0.8.6, 8.1.1.4 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compro
nvd
CVE-2020-14603P4MEDIUMCVSS 5.3≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14603 [MEDIUM] CVE-2020-14603: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyt
nvd
CVE-2020-14604P4MEDIUMCVSS 5.3≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14604 [MEDIUM] CVE-2020-14604: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyt
nvd
CVE-2021-35687P4MEDIUMCVSS 5.3≥ 8.0.7, ≤ 8.1.12022-01-19
CVE-2021-35687 [MEDIUM] CVE-2021-35687: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Servi
nvd
CVE-2019-2823P4MEDIUMCVSS 5.4≥ 8.0.5, ≤ 8.0.82019-07-23
CVE-2019-2823 [MEDIUM] CVE-2019-2823: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of O Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 8.0.5-8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Anal
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1≥ 8.0.7, ≤ 8.1.1v7.3.32019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2018-2661P4MEDIUMCVSS 6.1v7.3.5.0.0v7.3.5.1.0+8 more2018-01-18
CVE-2018-2661 [MEDIUM] CVE-2018-2661: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of O Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 7.3.5.x and 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd
CVE-2021-2140P4MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.1.02021-04-22
CVE-2021-2140 [MEDIUM] CVE-2021-2140: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Rules Framework). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5≥ 8.0.6, ≤ 8.0.92019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2021-32809P4MEDIUMCVSS 5.4≥ 8.0.7, ≤ 8.1.12021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2020-14601P4MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14601 [MEDIUM] CWE-79 CVE-2020-14601: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services
nvd
CVE-2020-14615P4MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.1.02020-07-15
CVE-2020-14615 [MEDIUM] CWE-79 CVE-2020-14615: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services
nvd