Oracle Financial Services Analytical Applications Infrastructure vulnerabilities

84 known vulnerabilities affecting oracle/financial_services_analytical_applications_infrastructure.

Total CVEs
84
CISA KEV
3
actively exploited
Public exploits
7
Exploited in wild
5
Severity breakdown
CRITICAL18HIGH28MEDIUM37LOW1

Vulnerabilities

Page 5 of 5
CVE-2015-9251MEDIUMCVSS 6.1≥ 7.3.3, ≤ 7.3.5≥ 8.0.0, ≤ 8.0.72018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2018-2661MEDIUMCVSS 6.1v7.3.5.0.0v7.3.5.1.0+8 more2018-01-18
CVE-2018-2661 [MEDIUM] CVE-2018-2661: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of O Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 7.3.5.x and 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyti
nvd
CVE-2017-12617HIGHCVSS 8.1KEVPoC≥ 7.3.3.0.0, ≤ 7.3.5.3.0≥ 8.0.0.0.0, ≤ 8.0.9.0.02017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-5645CRITICALCVSS 9.8PoC≥ 7.3.3.0.0, ≤ 7.3.3.0.2≥ 8.0.0.0.0, ≤ 8.0.7.0.02017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd