cbcvebase.

Oracle Flexcube Private Banking vulnerabilities

75 known vulnerabilities affecting oracle/flexcube_private_banking.

Total CVEs
75
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH22MEDIUM43LOW1

Vulnerabilities

Page 2 of 4
CVE-2020-11979P3HIGHCVSS 7.5v12.0.0v12.1.02020-10-01
CVE-2020-11979 [HIGH] CWE-379 CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it crea As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modifi
nvd
CVE-2016-8298P3HIGHCVSS 8.1v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-8298 [HIGH] CWE-284 CVE-2016-8298: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.
nvd
CVE-2021-2351P3HIGHCVSS 7.5v12.0.0v12.1.02021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2021-43859P3HIGHCVSS 7.5v12.1.02022-02-01
CVE-2021-43859 [HIGH] CWE-400 CVE-2021-43859: XStream is an open source java library to serialize objects to XML and back again. Versions prior to XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors an
nvd
CVE-2019-12423P3HIGHCVSS 7.5v12.0.0v12.1.02020-01-16
CVE-2019-12423 [HIGH] CWE-522 CVE-2019-12423: Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service. Typically, the service obtains the public key from a local keystore (JKS/PKCS12) by specifing the path of the keystore and the alias of the keystore entry
nvd
CVE-2018-11040P3HIGHCVSS 7.5v2.0.0.0v2.2.0.1+3 more2018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2019-17359P3HIGHCVSS 7.5v12.0.0v12.1.02019-10-08
CVE-2019-17359 [HIGH] CWE-770 CVE-2019-17359: The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory all The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.
nvd
CVE-2013-4316P3CRITICALCVSS 10.0v1.7v2.0+5 more2013-09-30
CVE-2013-4316 [CRITICAL] CWE-16 CVE-2013-4316: Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
nvd
CVE-2019-5427P3HIGHCVSS 7.5v12.0.0v12.1.02019-04-22
CVE-2019-5427 [HIGH] CWE-776 CVE-2019-5427: c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration du c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configuration due to missing protections against recursive entity expansion when loading configuration.
nvd
CVE-2016-8312P3HIGHCVSS 8.2v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-8312 [HIGH] CWE-284 CVE-2016-8312: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking
nvd
CVE-2020-5421P3MEDIUMCVSS 6.5v12.0.0v12.1.02020-09-19
CVE-2020-5421 [MEDIUM] CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and olde In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
nvd
CVE-2017-3476P3HIGHCVSS 7.1v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3476 [HIGH] CVE-2017-3476: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2020-27216P3HIGHCVSS 7.0v12.0.0v12.1.02020-10-23
CVE-2020-27216 [HIGH] CWE-378 CVE-2020-27216: In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alp In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a temporary sub directory in the shared temporary directory and race to comp
nvd
CVE-2017-10023P3MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10023 [MEDIUM] CVE-2017-10023: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful at
nvd
CVE-2017-10103P3MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10103 [MEDIUM] CWE-269 CVE-2017-10103: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Su
nvd
CVE-2017-10006P3MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10006 [MEDIUM] CVE-2017-10006: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2018-1257P3MEDIUMCVSS 6.5v2.0.0.0v2.2.0.1+3 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2020-13920P3MEDIUMCVSS 5.9v12.0.0v12.1.02020-09-10
CVE-2020-13920 [MEDIUM] CWE-306 CVE-2020-13920: Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the se Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method to rebind jmxrmi to something else. If an attacker creates another server to proxy the original, and bound that, he effectively bec
nvd
CVE-2018-10237P4MEDIUMCVSS 5.9v12.0.0v12.1.02018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1v12.0.0v12.1.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
Oracle Flexcube Private Banking vulnerabilities | cvebase