cbcvebase.

Oracle Flexcube Private Banking vulnerabilities

75 known vulnerabilities affecting oracle/flexcube_private_banking.

Total CVEs
75
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL9HIGH22MEDIUM43LOW1

Vulnerabilities

Page 4 of 4
CVE-2020-1950P4MEDIUMCVSS 5.5v12.0.0v12.1.02020-03-23
CVE-2020-1950 [MEDIUM] CWE-400 CVE-2020-1950: A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2020-1951P4MEDIUMCVSS 5.5v12.0.0v12.1.02020-03-23
CVE-2020-1951 [MEDIUM] CWE-835 CVE-2020-1951: A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in ver A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
nvd
CVE-2020-9489P4MEDIUMCVSS 5.5v12.0.0v12.1.02020-04-27
CVE-2020-9489 [MEDIUM] CWE-835 CVE-2020-9489: A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or c A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser
nvd
CVE-2020-9488P4LOWCVSS 3.7v12.0.0v12.1.02020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2017-10010P4MEDIUMCVSS 4.6v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10010 [MEDIUM] CVE-2017-10010: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: FileUploads). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful a
nvd
CVE-2016-8308P4MEDIUMCVSS 4.3v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-8308 [MEDIUM] CVE-2016-8308: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Succ
nvd
CVE-2017-10022P4MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10022 [MEDIUM] CVE-2017-10022: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful at
nvd
CVE-2017-10009P4MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10009 [MEDIUM] CVE-2017-10009: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-10007P4MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10007 [MEDIUM] CVE-2017-10007: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2017-3473P4MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-04-24
CVE-2017-3473 [MEDIUM] CVE-2017-3473: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successf
nvd
CVE-2016-5614P4MEDIUMCVSS 4.3v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-5614 [MEDIUM] CWE-200 CVE-2016-5614: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Bankin
nvd
CVE-2017-10008P4MEDIUMCVSS 4.3v2.0.0v2.0.1+2 more2017-08-08
CVE-2017-10008 [MEDIUM] CVE-2017-10008: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful
nvd
CVE-2016-5493P4MEDIUMCVSS 4.2v12.0.1v12.0.2+1 more2016-10-25
CVE-2016-5493 [MEDIUM] CWE-284 CVE-2016-5493: Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Servi Unspecified vulnerability in the Oracle FLEXCUBE Private Banking component in Oracle Financial Services Applications 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2017-3477P4MEDIUMCVSS 4.2v12.0.0v12.1.02017-04-24
CVE-2017-3477 [MEDIUM] CVE-2017-3477: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking. Successful attacks of t
nvd
CVE-2016-8313P4MEDIUMCVSS 4.1v2.0.1v2.2.0+1 more2017-01-27
CVE-2016-8313 [MEDIUM] CWE-200 CVE-2016-8313: Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Bankin
nvd
Oracle Flexcube Private Banking vulnerabilities | cvebase