Oracle Flexcube Private Banking vulnerabilities
75 known vulnerabilities affecting oracle/flexcube_private_banking.
Total CVEs
75
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH22MEDIUM43LOW1
Vulnerabilities
Page 3 of 4
CVE-2018-15756HIGHCVSS 7.5v12.0.1v12.0.3+1 more2018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2018-11775HIGHCVSS 7.4v2.0.0.0v2.2.0.1+3 more2018-09-10
CVE-2018-11775 [HIGH] CWE-295 CVE-2018-11775: TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which coul
TLS hostname verification when using the Apache ActiveMQ Client before 5.15.6 was missing which could make the client vulnerable to a MITM attack between a Java application using the ActiveMQ client and the ActiveMQ server. This is now enabled by default.
nvd
CVE-2018-8032MEDIUMCVSS 6.1v12.0.0v12.1.02018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2018-11040HIGHCVSS 7.5v2.0.0.0v2.2.0.1+3 more2018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2018-1257MEDIUMCVSS 6.5v2.0.0.0v2.2.0.1+3 more2018-05-11
CVE-2018-1257 [MEDIUM] CVE-2018-1257: Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupport
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of
nvd
CVE-2018-10237MEDIUMCVSS 5.9v12.0.0v12.1.02018-04-26
CVE-2018-10237 [MEDIUM] CWE-770 CVE-2018-10237: Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the CompoundOrdering class (when serialized with
nvd
CVE-2017-10023MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10023 [MEDIUM] CVE-2017-10023: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful at
nvd
CVE-2017-10010MEDIUMCVSS 4.6v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10010 [MEDIUM] CVE-2017-10010: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: FileUploads). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful a
nvd
CVE-2017-10022MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10022 [MEDIUM] CVE-2017-10022: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful at
nvd
CVE-2017-10007MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10007 [MEDIUM] CVE-2017-10007: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-10009MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10009 [MEDIUM] CVE-2017-10009: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-10103MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10103 [MEDIUM] CWE-269 CVE-2017-10103: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Su
nvd
CVE-2017-10008MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10008 [MEDIUM] CVE-2017-10008: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-10011MEDIUMCVSS 5.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10011 [MEDIUM] CVE-2017-10011: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle FLEXCUBE Private Banking executes to com
nvd
CVE-2017-10005MEDIUMCVSS 6.1v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10005 [MEDIUM] CVE-2017-10005: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successfu
nvd
CVE-2017-10012MEDIUMCVSS 5.4v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10012 [MEDIUM] CVE-2017-10012: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful at
nvd
CVE-2017-10006MEDIUMCVSS 6.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10006 [MEDIUM] CVE-2017-10006: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-3476HIGHCVSS 7.1v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3476 [HIGH] CVE-2017-3476: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-3472HIGHCVSS 8.1v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3472 [HIGH] CVE-2017-3472: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Portfolio Management). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Suc
nvd
CVE-2017-3475MEDIUMCVSS 5.0v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3475 [MEDIUM] CVE-2017-3475: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. While th
nvd