Oracle Financial Services Hedge Management And Ifrs Valuations vulnerabilities
8 known vulnerabilities affecting oracle/financial_services_hedge_management_and_ifrs_valuations.
Total CVEs
8
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL1HIGH2MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2020-11022MEDIUMCVSS 6.1ExploitedPoC≥ 8.0.6, ≤ 8.0.8v8.1.02020-04-29
CVE-2020-11022 [MEDIUM] CWE-79 CVE-2020-11022: In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sa
In jQuery starting with 1.12.0 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e. .html(), .append(), and others) may execute untrusted code. This problem is patched in jQuery 3.5.0.
nvd
CVE-2020-2935HIGHCVSS 7.1≥ 8.0.6, ≤ 8.0.82020-04-15
CVE-2020-2935 [HIGH] CVE-2020-2935: Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations product of Oracl
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations product of Oracle Financial Services Applications (component: User Interface). Supported versions that are affected are 8.0.6 - 8.0.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Hedge Manag
nvd
CVE-2019-11358MEDIUMCVSS 6.1ExploitedPoC≥ 8.0.4, ≤ 8.0.7v8.1.02019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2018-2725HIGHCVSS 8.1v8.0.52018-01-18
CVE-2018-2725 [HIGH] CVE-2018-2725: Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Ora
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Hedge Managem
nvd
CVE-2018-2719MEDIUMCVSS 6.1v8.0.5.0.02018-01-18
CVE-2018-2719 [MEDIUM] CVE-2018-2719: Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Ora
Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Hedge Mana
nvd
CVE-2015-9251MEDIUMCVSS 6.1≥ 8.0.4, ≤ 8.0.72018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
CVE-2017-15707MEDIUMCVSS 6.2v8.0.4v8.0.52017-12-01
CVE-2017-15707 [MEDIUM] CWE-20 CVE-2017-15707: In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulne
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv8.0.4v8.0.52017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd