cbcvebase.

Oracle Flexcube Private Banking vulnerabilities

75 known vulnerabilities affecting oracle/flexcube_private_banking.

Total CVEs
75
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH22MEDIUM43LOW1

Vulnerabilities

Page 3 of 4
CVE-2020-1945P4MEDIUMCVSS 6.3v12.0.0v12.1.02020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2019-12406P4MEDIUMCVSS 6.5v12.0.0v12.1.02019-11-06
CVE-2019-12406 [MEDIUM] CWE-770 CVE-2019-12406: Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a Apache CXF before 3.3.4 and 3.2.11 does not restrict the number of message attachments present in a given message. This leaves open the possibility of a denial of service type attack, where a malicious user crafts a message containing a very large number of message attachments. From the 3.3.4 and 3.2.11 releases, a default limit of 50 message attachm
nvd
CVE-2019-17573P3MEDIUMCVSS 6.1v12.0.0v12.1.02020-01-16
CVE-2019-17573 [MEDIUM] CWE-79 CVE-2019-17573: By default, Apache CXF creates a /services page containing a listing of the available endpoint names By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into the web page. Please note that the attack exploits a feature which is not typically not present in mod
nvd
CVE-2020-27218P4MEDIUMCVSS 4.8v12.0.0v12.1.02020-11-28
CVE-2020-27218 [MEDIUM] CWE-226 CVE-2020-27218: In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.al In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely but not consumed by the applicati
nvd
CVE-2019-10247P4MEDIUMCVSS 5.3v12.0.0v12.1.02019-04-22
CVE-2019-10247 [MEDIUM] CWE-213 CVE-2019-10247: In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the ser In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path. The default server behavior on je
nvd
CVE-2019-10246P4MEDIUMCVSS 5.3v12.0.0v12.1.02019-04-22
CVE-2019-10246 [MEDIUM] CWE-213 CVE-2019-10246: In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in the configured base resource dire
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3v12.0.0v12.1.02020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2020-1941P4MEDIUMCVSS 6.1v12.0.0v12.1.02020-05-14
CVE-2020-1941 [MEDIUM] CWE-79 CVE-2020-1941: In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue.
nvd
CVE-2017-10012P4MEDIUMCVSS 5.4v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10012 [MEDIUM] CVE-2017-10012: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful at
nvd
CVE-2017-3478P4MEDIUMCVSS 5.4v12.0.0v12.1.02017-04-24
CVE-2017-3478 [MEDIUM] CVE-2017-3478: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of t
nvd
CVE-2016-8300P4MEDIUMCVSS 5.3v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-8300 [MEDIUM] CWE-284 CVE-2016-8300: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Bank
nvd
CVE-2016-5623P4MEDIUMCVSS 5.4v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-5623 [MEDIUM] CWE-254 CVE-2016-5623: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Bankin
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v12.0.0v12.1.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2017-10005P4MEDIUMCVSS 6.1v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10005 [MEDIUM] CVE-2017-10005: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successfu
nvd
CVE-2016-8282P4MEDIUMCVSS 6.1v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-8282 [MEDIUM] CWE-284 CVE-2016-8282: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banki
nvd
CVE-2017-3479P4MEDIUMCVSS 5.4v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3479 [MEDIUM] CVE-2017-3479: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successf
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5v12.0.0v12.1.02019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2017-10011P4MEDIUMCVSS 5.5v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10011 [MEDIUM] CVE-2017-10011: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle FLEXCUBE Private Banking executes to com
nvd
CVE-2017-3475P4MEDIUMCVSS 5.0v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3475 [MEDIUM] CVE-2017-3475: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. While th
nvd
CVE-2017-3471P4MEDIUMCVSS 4.7v12.0.0v12.1.02017-04-24
CVE-2017-3471 [MEDIUM] CVE-2017-3471: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks req
nvd
Oracle Flexcube Private Banking vulnerabilities | cvebase