Oracle Flexcube Universal Banking vulnerabilities

95 known vulnerabilities affecting oracle/flexcube_universal_banking.

Total CVEs
95
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM71LOW4

Vulnerabilities

Page 1 of 5
CVE-2026-21978MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.8.0.0.02026-01-20
CVE-2026-21978 [MEDIUM] CVE-2026-21978: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Relationship Pricing). Supported versions that are affected are 14.0.0.0.0-14.8.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful at
nvd
CVE-2023-22117MEDIUMCVSS 5.4≥ 14.0.0, ≤ 14.3.0≥ 14.5.0, ≤ 14.7.0+2 more2023-10-17
CVE-2023-22117 [MEDIUM] CVE-2023-22117: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Succe
nvd
CVE-2023-22119MEDIUMCVSS 5.9≥ 14.0.0, ≤ 14.3.0≥ 14.5.0, ≤ 14.7.0+2 more2023-10-17
CVE-2023-22119 [MEDIUM] CVE-2023-22119: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Suc
nvd
CVE-2023-22118MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.3.0≥ 14.5.0, ≤ 14.7.0+2 more2023-10-17
CVE-2023-22118 [MEDIUM] CVE-2023-22118: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Succe
nvd
CVE-2022-21544HIGHCVSS 7.1≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21544 [HIGH] CVE-2022-21544: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2022-21579MEDIUMCVSS 6.4≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21579 [MEDIUM] CVE-2022-21579: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2022-21578MEDIUMCVSS 6.7≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21578 [MEDIUM] CVE-2022-21578: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2022-21428MEDIUMCVSS 6.7≥ 12.1.0, ≤ 12.4≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21428 [MEDIUM] CVE-2022-21428: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2022-21577MEDIUMCVSS 6.4≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21577 [MEDIUM] CVE-2022-21577: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2022-21576MEDIUMCVSS 6.4≥ 14.0.0, ≤ 14.3.0v12.3.0+2 more2022-07-19
CVE-2022-21576 [MEDIUM] CVE-2022-21576: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successf
nvd
CVE-2022-21472MEDIUMCVSS 5.9≥ 14.0.0, ≤ 14.3.0v12.4.0+1 more2022-04-19
CVE-2022-21472 [MEDIUM] CVE-2022-21472: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful att
nvd
CVE-2022-23437MEDIUMCVSS 6.5v12.4.02022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2021-45105MEDIUMCVSS 5.9≥ 12.1.0, ≤ 12.4≥ 14.0.0, ≤ 14.3.0+2 more2021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-41973MEDIUMCVSS 6.5≥ 14.0, ≤ 14.3v14.52021-11-01
CVE-2021-41973 [MEDIUM] CWE-835 CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
nvd
CVE-2021-37714HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v14.52021-08-18
CVE-2021-37714 [HIGH] CWE-248 CVE-2021-37714: jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse u jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supply content that causes the parser to get stuck (loop indefinitely until cancelled), to complete more slowly than usual, or to throw a
nvd
CVE-2021-2323MEDIUMCVSS 5.9≥ 14.0.0, ≤ 14.4.0v12.3.0+1 more2021-07-21
CVE-2021-2323 [MEDIUM] CVE-2021-2323: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Flex-Branch). Supported versions that are affected are 12.3, 12.4, 14.0-14.4 and . Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attac
nvd
CVE-2021-2324MEDIUMCVSS 4.6≥ 12.0.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.4.02021-07-21
CVE-2021-2324 [MEDIUM] CVE-2021-2324: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Loans And Deposits). Supported versions that are affected are 12.0-12.4, 14.0-14.4 and . Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful at
nvd
CVE-2021-35515HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4.0+1 more2021-07-13
CVE-2021-35515 [HIGH] CWE-834 CVE-2021-35515: When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2021-36090HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4+1 more2021-07-13
CVE-2021-36090 [HIGH] CWE-130 CVE-2021-36090: When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memo When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' zip package.
nvd
CVE-2021-35517HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4+1 more2021-07-13
CVE-2021-35517 [HIGH] CWE-130 CVE-2021-35517: When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memo When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
nvd