Oracle Financial Services Funds Transfer Pricing vulnerabilities

8 known vulnerabilities affecting oracle/financial_services_funds_transfer_pricing.

Total CVEs
8
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
HIGH3MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2020-11022MEDIUMCVSS 6.1ExploitedPoCv8.0.6v8.0.7+1 more2020-04-29
CVE-2020-11022 [MEDIUM] CWE-79 CVE-2020-11022: In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted source In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2020-2941HIGHCVSS 7.1v8.0.6v8.0.72020-04-15
CVE-2020-2941 [HIGH] CVE-2020-2941: Vulnerability in the Oracle Financial Services Funds Transfer Pricing product of Oracle Financial Se Vulnerability in the Oracle Financial Services Funds Transfer Pricing product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 and 8.0.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Funds Transfer Pricing.
nvd
CVE-2019-0227HIGHCVSS 7.5PoC≥ 8.0.2, ≤ 8.0.72019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoC≥ 8.0.4, ≤ 8.0.7v8.1.02019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2018-8032MEDIUMCVSS 6.1≥ 8.0.2, ≤ 8.0.72018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-2729HIGHCVSS 8.1v6.1.0.0.0v6.1.0.2.2+11 more2018-01-18
CVE-2018-2729 [HIGH] CVE-2018-2729: Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Funds Transfer Pric
nvd
CVE-2015-9251MEDIUMCVSS 6.1≥ 8.0.4, ≤ 8.0.72018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2018-2728MEDIUMCVSS 6.1v6.1.0.0.0v6.1.0.2.2+11 more2018-01-18
CVE-2018-2728 [MEDIUM] CVE-2018-2728: Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Services Applications (subcomponent: User Interface). Supported versions that are affected are 6.1.x and 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Funds Transfer P
nvd