Oracle Flexcube Investor Servicing vulnerabilities
45 known vulnerabilities affecting oracle/flexcube_investor_servicing.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH10MEDIUM30LOW3
Vulnerabilities
Page 2 of 3
CVE-2018-3028MEDIUMCVSS 6.3v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3028 [MEDIUM] CVE-2018-3028: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-3034MEDIUMCVSS 5.4v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3034 [MEDIUM] CVE-2018-3034: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-3030MEDIUMCVSS 6.5v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3030 [MEDIUM] CVE-2018-3030: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-3032MEDIUMCVSS 5.4v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3032 [MEDIUM] CVE-2018-3032: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-3033MEDIUMCVSS 5.3v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3033 [MEDIUM] CVE-2018-3033: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.
nvd
CVE-2018-3029MEDIUMCVSS 5.3v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3029 [MEDIUM] CVE-2018-3029: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. S
nvd
CVE-2018-3031MEDIUMCVSS 5.4v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-3031 [MEDIUM] CVE-2018-3031: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. Su
nvd
CVE-2018-2898MEDIUMCVSS 6.1v12.0.4v12.1.0+2 more2018-07-18
CVE-2018-2898 [MEDIUM] CVE-2018-2898: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.4, 12.1.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing. S
nvd
CVE-2018-10237MEDIUMCVSS 5.9v12.1.0v12.3.0+3 more2018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2018-2746HIGHCVSS 7.1v12.0.4v12.1.0+2 more2018-04-19
CVE-2018-2746 [HIGH] CVE-2018-2746: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful
nvd
CVE-2018-2747MEDIUMCVSS 6.5v12.0.4v12.1.0+2 more2018-04-19
CVE-2018-2747 [MEDIUM] CVE-2018-2747: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2018-2748MEDIUMCVSS 6.1v12.0.4v12.1.0+2 more2018-04-19
CVE-2018-2748 [MEDIUM] CVE-2018-2748: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successf
nvd
CVE-2018-2749MEDIUMCVSS 5.4v12.0.4v12.1.0+2 more2018-04-19
CVE-2018-2749 [MEDIUM] CVE-2018-2749: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2017-3488MEDIUMCVSS 6.5v12.0.1v12.0.2+5 more2017-04-24
CVE-2017-3488 [MEDIUM] CVE-2017-3488: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE
nvd
CVE-2017-3288MEDIUMCVSS 5.4v12.0.1v12.0.2+5 more2017-04-24
CVE-2017-3288 [MEDIUM] CVE-2017-3288: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE
nvd
CVE-2017-3489MEDIUMCVSS 5.4v12.0.1v12.0.2+5 more2017-04-24
CVE-2017-3489 [MEDIUM] CVE-2017-3489: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Security Management System). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise
nvd
CVE-2017-3487LOWCVSS 3.1v12.0.1v12.0.2+5 more2017-04-24
CVE-2017-3487 [LOW] CVE-2017-3487: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Inv
nvd
CVE-2017-5645CRITICALCVSS 9.8PoCv12.0.4v12.1.0+3 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-8315HIGHCVSS 8.1v12.0.1v12.0.2+3 more2017-01-27
CVE-2016-8315 [HIGH] CWE-284 CVE-2016-8315: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Infrastructure Code). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Inves
cvelistv5nvd
CVE-2016-8306MEDIUMCVSS 5.4v12.0.1v12.0.2+3 more2017-01-27
CVE-2016-8306 [MEDIUM] CWE-254 CVE-2016-8306: Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Appli
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing
cvelistv5nvd