Oracle Flexcube Core Banking vulnerabilities

15 known vulnerabilities affecting oracle/flexcube_core_banking.

Total CVEs
15
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM10LOW2

Vulnerabilities

Page 1 of 1
CVE-2021-29425MEDIUMCVSS 4.8≥ 11.6.0, ≤ 11.8.0v5.2.0+1 more2021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2020-27216HIGHCVSS 7.0≥ 11.5.0, ≤ 11.9.02020-10-23
CVE-2020-27216 [HIGH] CWE-378 CVE-2020-27216: In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alp In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to comp
nvd
CVE-2020-10683CRITICALCVSS 9.8v11.7.0v11.8.0+2 more2020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2020-9488LOWCVSS 3.7≥ 11.5.0, ≤ 11.7.0v5.2.02020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2020-2955MEDIUMCVSS 6.3v4.02020-04-15
CVE-2020-2955 [MEDIUM] CVE-2020-2955: Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Transaction Processing). The supported version that is affected is 4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this vulnerability
nvd
CVE-2019-0227HIGHCVSS 7.5PoCv11.7.0v11.8.0+2 more2019-05-01
CVE-2019-0227 [HIGH] CWE-918 CVE-2019-0227: A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that wa A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to t
nvd
CVE-2019-10241MEDIUMCVSS 6.1≥ 11.5.0, ≤ 11.7.0v5.2.02019-04-22
CVE-2019-10241 [MEDIUM] CWE-79 CVE-2019-10241: In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vul In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents.
nvd
CVE-2019-10247MEDIUMCVSS 5.3≥ 11.5.0, ≤ 11.7.0v5.2.02019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2019-10246MEDIUMCVSS 5.3≥ 11.5.0, ≤ 11.7.0v5.2.02019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2018-8032MEDIUMCVSS 6.1v11.7.0v11.8.0+2 more2018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-2807MEDIUMCVSS 6.1v11.5.0v11.6.0+1 more2018-04-19
CVE-2018-2807 [MEDIUM] CVE-2018-2807: Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Application Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Securities). Supported versions that are affected are 11.5.0, 11.6.0 and 11.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks requir
nvd
CVE-2016-8323MEDIUMCVSS 5.4v5.1.0v5.2.0+1 more2017-01-27
CVE-2016-8323 [MEDIUM] CWE-284 CVE-2016-8323: Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Application Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this
cvelistv5nvd
CVE-2016-8324MEDIUMCVSS 5.3v5.1.0v5.2.0+1 more2017-01-27
CVE-2016-8324 [MEDIUM] CWE-284 CVE-2016-8324: Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Application Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of thi
cvelistv5nvd
CVE-2016-8322MEDIUMCVSS 4.3v5.1.0v5.2.0+1 more2017-01-27
CVE-2016-8322 [MEDIUM] CWE-200 CVE-2016-8322: Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Application Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this
cvelistv5nvd
CVE-2016-8314LOWCVSS 3.1v5.1.0v5.2.0+1 more2017-01-27
CVE-2016-8314 [LOW] CWE-254 CVE-2016-8314: Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Application Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking. Successful attacks of this
cvelistv5nvd