Oracle Flexcube Investor Servicing vulnerabilities
45 known vulnerabilities affecting oracle/flexcube_investor_servicing.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM30LOW3
Vulnerabilities
Page 1 of 3
CVE-2017-5645P1CRITICALCVSS 9.8PoCv12.0.4v12.1.0+3 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2019-13990P3CRITICALCVSS 9.8v12.1.0v12.3.0+3 more2019-07-26
CVE-2019-13990 [CRITICAL] CWE-611 CVE-2019-13990: initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
nvd
CVE-2026-21973P3HIGHCVSS 8.1v14.5.0.15.0v14.7.0.8.0+1 more2026-01-20
CVE-2026-21973 [HIGH] CVE-2026-21973: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Security Management System). Supported versions that are affected are 14.5.0.15.0, 14.7.0.8.0 and 14.8.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor S
nvd
CVE-2019-12402P3HIGHCVSS 7.5v12.1.0v12.3.0+3 more2019-08-30
CVE-2019-12402 [HIGH] CWE-835 CVE-2019-12402: The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get int
The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker can choose the file names inside of an archive created by Compress.
nvd
CVE-2018-3035P3HIGHCVSS 8.1v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3035 [HIGH] CVE-2018-3035: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Succ
nvd
CVE-2020-14569P3HIGHCVSS 8.1v12.1.0v12.3.0+3 more2020-07-15
CVE-2020-14569 [HIGH] CVE-2020-14569: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.
nvd
CVE-2016-8315P3HIGHCVSS 8.1v12.0.1v12.0.2+3 more2017-01-27
CVE-2016-8315 [HIGH] CWE-284 CVE-2016-8315: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure Code). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Inves
nvd
CVE-2019-2841P3HIGHCVSS 8.1v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2841 [HIGH] CVE-2019-2841: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle F
nvd
CVE-2018-1000632P3HIGHCVSS 7.5v12.0.4v12.1.0+3 more2018-08-20
CVE-2018-1000632 [HIGH] CWE-91 CVE-2018-1000632: dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Elemen
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability app
nvd
CVE-2021-2351P3HIGHCVSS 7.5v12.0.4v12.1.0+4 more2021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2018-2746P3HIGHCVSS 7.1v12.0.4v12.1.0+2 more2018-04-19
CVE-2018-2746 [HIGH] CVE-2018-2746: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful
nvd
CVE-2020-2723P3HIGHCVSS 7.1≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2723 [HIGH] CVE-2020-2723: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successful
nvd
CVE-2018-2747P3MEDIUMCVSS 6.5v12.0.4v12.1.0+2 more2018-04-19
CVE-2018-2747 [MEDIUM] CVE-2018-2747: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2020-2721P3MEDIUMCVSS 6.5≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.1.02020-01-15
CVE-2020-2721 [MEDIUM] CVE-2020-2721: Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applica
Vulnerability in the Oracle FLEXCUBE Investor Servicing product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Successfu
nvd
CVE-2017-3488P3MEDIUMCVSS 6.5v12.0.1v12.0.2+5 more2017-04-24
CVE-2017-3488 [MEDIUM] CVE-2017-3488: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE
nvd
CVE-2018-3028P3MEDIUMCVSS 6.3v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3028 [MEDIUM] CVE-2018-3028: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-3030P3MEDIUMCVSS 6.5v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3030 [MEDIUM] CVE-2018-3030: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v12.1.0v12.3.0+3 more2018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2020-1945P4MEDIUMCVSS 6.3v12.1.0v12.3.0+3 more2020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2019-2847P4MEDIUMCVSS 5.7v12.0.1v12.0.3+6 more2019-07-23
CVE-2019-2847 [MEDIUM] CVE-2019-2847: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.3, 12.0.4, 12.1.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
nvd
1 / 3Next →