cbcvebase.

Oracle Financial Services Analytical Applications Infrastructure vulnerabilities

90 known vulnerabilities affecting oracle/financial_services_analytical_applications_infrastructure.

Total CVEs
90
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
8
Severity breakdown
CRITICAL18HIGH30MEDIUM41LOW1

Vulnerabilities

Page 5 of 5
CVE-2021-32808P4MEDIUMCVSS 5.4≥ 8.0.7, ≤ 8.1.12021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2020-27193P4MEDIUMCVSS 6.1≥ 8.0.6, ≤ 8.0.9v8.1.0+1 more2020-11-12
CVE-2020-27193 [MEDIUM] CWE-79 CVE-2020-27193: A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows rem A cross-site scripting (XSS) vulnerability in the Color Dialog plugin for CKEditor 4.15.0 allows remote attackers to run arbitrary web script after persuading a user to copy and paste crafted HTML code into one of editor inputs.
nvd
CVE-2021-36374P4MEDIUMCVSS 5.5≥ 8.0.6, ≤ 8.1.12021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2021-37695P4MEDIUMCVSS 5.4≥ 8.0.7, ≤ 8.1.1v8.0.32021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
nvd
CVE-2022-24728P4MEDIUMCVSS 5.4≥ 8.0.7.0.0, ≤ 8.1.0.0.0v8.1.1.0+2 more2022-03-16
CVE-2022-24728 [MEDIUM] CWE-79 CVE-2022-24728: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been disco CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. T
nvd
CVE-2026-34321P4MEDIUMCVSS 4.8v8.0.7.9.0v8.0.8.7.0+1 more2026-04-21
CVE-2026-34321 [MEDIUM] CWE-285 CVE-2026-34321: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
nvd
CVE-2021-36373P4MEDIUMCVSS 5.5≥ 8.0.6, ≤ 8.1.12021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd
CVE-2020-9488P4LOWCVSS 3.7≥ 8.0.6.0.0, ≤ 8.1.0.0.02020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2021-35686P4MEDIUMCVSS 4.3≥ 8.0.7, ≤ 8.1.12022-01-19
CVE-2021-35686 [MEDIUM] CVE-2021-35686: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Unified Metadata Manager). Supported versions that are affected are 8.0.7-8.1.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Servic
nvd
CVE-2020-14684P4MEDIUMCVSS 4.3≥ 8.0.6.0.0, ≤ 8.1.0.0.02020-07-15
CVE-2020-14684 [MEDIUM] CVE-2020-14684: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Ora Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analyt
nvd
Oracle Financial Services Analytical Applications Infrastructure vulnerabilities | cvebase