Oracle Flexcube Investor Servicing vulnerabilities
45 known vulnerabilities affecting oracle/flexcube_investor_servicing.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM30LOW3
Vulnerabilities
Page 1 of 3
CVE-2026-21973HIGHCVSS 8.1v14.5.0.15.0v14.7.0.8.0+1 more2026-01-20
CVE-2026-21973 [HIGH] CVE-2026-21973: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 14.5.0.15.0, 14.7.0.8.0 and 14.8.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor S
nvd
CVE-2021-2351HIGHCVSS 7.5v12.0.4v12.1.0+4 more2021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-14569HIGHCVSS 8.1v12.1.0v12.3.0+3 more2020-07-15
CVE-2020-14569 [HIGH] CVE-2020-14569: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.
nvd
CVE-2020-1945MEDIUMCVSS 6.3v12.1.0v12.3.0+3 more2020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2020-2723HIGHCVSS 7.1≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2723 [HIGH] CVE-2020-2723: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful
nvd
CVE-2020-2720MEDIUMCVSS 5.4≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2720 [MEDIUM] CVE-2020-2720: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successfu
nvd
CVE-2020-2724MEDIUMCVSS 4.3≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2724 [MEDIUM] CVE-2020-2724: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successfu
nvd
CVE-2020-2721MEDIUMCVSS 6.5≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2721 [MEDIUM] CVE-2020-2721: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successfu
nvd
CVE-2020-2722MEDIUMCVSS 5.4≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2722 [MEDIUM] CVE-2020-2722: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successf
nvd
CVE-2019-10219MEDIUMCVSS 6.1v12.0.4v12.1.0+4 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-12402HIGHCVSS 7.5v12.1.0v12.3.0+3 more2019-08-30
CVE-2019-12402 [HIGH] CWE-835 CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get int
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
nvd
CVE-2019-13990CRITICALCVSS 9.8v12.1.0v12.3.0+3 more2019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd
CVE-2019-2841HIGHCVSS 8.1v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2841 [HIGH] CVE-2019-2841: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle F
nvd
CVE-2019-2736MEDIUMCVSS 6.1v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2736 [MEDIUM] CVE-2019-2736: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracl
nvd
CVE-2019-2847MEDIUMCVSS 5.7v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2847 [MEDIUM] CVE-2019-2847: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
nvd
CVE-2019-2843MEDIUMCVSS 5.4v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2843 [MEDIUM] CVE-2019-2843: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
nvd
CVE-2019-2846MEDIUMCVSS 5.3v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2846 [MEDIUM] CVE-2019-2846: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracl
nvd
CVE-2019-2845LOWCVSS 3.5v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2845 [LOW] CVE-2019-2845: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FL
nvd
CVE-2018-1000632HIGHCVSS 7.5v12.0.4v12.1.0+3 more2018-08-20
CVE-2018-1000632 [HIGH] CWE-91 CVE-2018-1000632: dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Elemen
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability app
nvd
CVE-2018-3035HIGHCVSS 8.1v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3035 [HIGH] CVE-2018-3035: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Succ
nvd
1 / 3Next →