Oracle Flexcube Universal Banking vulnerabilities
95 known vulnerabilities affecting oracle/flexcube_universal_banking.
Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH20MEDIUM71LOW4
Vulnerabilities
Page 1 of 5
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomware≥ 12.1.0, ≤ 12.4≥ 14.0.0, ≤ 14.3.0+2 more2021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2020-11987P2HIGHCVSS 8.2≥ 14.1.0, ≤ 14.4.02021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2018-2648P3HIGHCVSS 8.8v11.3.0v11.4.0+7 more2018-01-18
CVE-2018-2648 [HIGH] CVE-2018-2648: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise O
nvd
CVE-2018-3015P3HIGHCVSS 8.1v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-3015 [HIGH] CVE-2018-3015: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP
nvd
CVE-2016-5607P3HIGHCVSS 8.8v11.3.0v11.4.0+5 more2016-10-25
CVE-2016-5607 [HIGH] CWE-284 CVE-2016-5607: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Ser
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to INFRA.
nvd
CVE-2019-2754P3HIGHCVSS 8.1≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2754 [HIGH] CVE-2019-2754: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Ba
nvd
CVE-2021-35515P3HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4.0+1 more2021-07-13
CVE-2021-35515 [HIGH] CWE-834 CVE-2021-35515: When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2018-2649P3HIGHCVSS 8.1v11.3.0v11.4.0+7 more2018-01-18
CVE-2018-2649 [HIGH] CVE-2018-2649: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise O
nvd
CVE-2016-8297P3HIGHCVSS 8.1v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8297 [HIGH] CWE-284 CVE-2016-8297: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Uni
nvd
CVE-2021-37714P3HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v14.52021-08-18
CVE-2021-37714 [HIGH] CWE-248 CVE-2021-37714: jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse u
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw a
nvd
CVE-2021-36090P3HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4+1 more2021-07-13
CVE-2021-36090 [HIGH] CWE-130 CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memo
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
nvd
CVE-2021-35516P3HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4.0+1 more2021-07-13
CVE-2021-35516 [HIGH] CWE-130 CVE-2021-35516: When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memor
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2021-35517P3HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4+1 more2021-07-13
CVE-2021-35517 [HIGH] CWE-130 CVE-2021-35517: When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memo
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
nvd
CVE-2016-5619P3HIGHCVSS 8.1v11.3.0v11.4.0+5 more2016-10-25
CVE-2016-5619 [HIGH] CWE-284 CVE-2016-5619: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Ser
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA, a different vulnerability than CVE-2016-5620.
nvd
CVE-2016-8310P3HIGHCVSS 7.3v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8310 [HIGH] CWE-254 CVE-2016-8310: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Un
nvd
CVE-2019-12399P3HIGHCVSS 7.5v14.4.02020-01-14
CVE-2019-12399 [HIGH] CWE-319 CVE-2019-12399: When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configur
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect c
nvd
CVE-2017-10363P3HIGHCVSS 7.1v11.3v11.4.0+7 more2017-10-19
CVE-2017-10363 [HIGH] CVE-2017-10363: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security). Supported versions that are affected are 11.3, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
nvd
CVE-2017-10085P3HIGHCVSS 7.1v11.3.0v11.4.0+6 more2017-08-08
CVE-2017-10085 [HIGH] CVE-2017-10085: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle
nvd
CVE-2018-2746P3HIGHCVSS 7.1v11.3.0v11.4.0+8 more2018-04-19
CVE-2018-2746 [HIGH] CVE-2018-2746: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successful
nvd
CVE-2026-21978P3MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.8.0.0.02026-01-20
CVE-2026-21978 [MEDIUM] CVE-2026-21978: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Relationship Pricing). Supported versions that are affected are 14.0.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful at
nvd
1 / 5Next →