Oracle Flexcube Universal Banking vulnerabilities

95 known vulnerabilities affecting oracle/flexcube_universal_banking.

Total CVEs
95
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH20MEDIUM71LOW4

Vulnerabilities

Page 2 of 5
CVE-2021-35516HIGHCVSS 7.5≥ 14.0.0, ≤ 14.3.0v12.4.0+1 more2021-07-13
CVE-2021-35516 [HIGH] CWE-130 CVE-2021-35516: When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memor When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2021-30129MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.3.0v14.52021-07-12
CVE-2021-30129 [MEDIUM] CWE-772 CVE-2021-30129: A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing a A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
nvd
CVE-2021-31811MEDIUMCVSS 5.5≥ 14.0.0, ≤ 14.3.0v14.52021-06-12
CVE-2021-31811 [MEDIUM] CWE-789 CVE-2021-31811: In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading th In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
nvd
CVE-2021-27807MEDIUMCVSS 5.5≥ 14.0.0, ≤ 14.3.0v14.5.02021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27906MEDIUMCVSS 5.5≥ 14.0.0, ≤ 14.3.0v14.5.02021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2020-11987HIGHCVSS 8.2≥ 14.1.0, ≤ 14.4.02021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2020-14887MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.4.0v12.3.02020-10-21
CVE-2020-14887 [MEDIUM] CVE-2020-14887: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3.0 and 14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attac
nvd
CVE-2020-2699HIGHCVSS 7.1≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2699 [HIGH] CVE-2020-2699: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful at
nvd
CVE-2020-2685MEDIUMCVSS 5.4≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2685 [MEDIUM] CVE-2020-2685: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2020-2700MEDIUMCVSS 4.3≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2700 [MEDIUM] CVE-2020-2700: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2020-2684MEDIUMCVSS 6.5≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2684 [MEDIUM] CVE-2020-2684: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2020-2683MEDIUMCVSS 5.4≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2683 [MEDIUM] CVE-2020-2683: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2019-12399HIGHCVSS 7.5v14.4.02020-01-14
CVE-2019-12399 [HIGH] CWE-319 CVE-2019-12399: When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configur When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect c
nvd
CVE-2019-2754HIGHCVSS 8.1≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2754 [HIGH] CVE-2019-2754: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Ba
nvd
CVE-2019-2790MEDIUMCVSS 5.4≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2790 [MEDIUM] CVE-2019-2790: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2019-2839MEDIUMCVSS 5.3≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.2.02019-07-23
CVE-2019-2839 [MEDIUM] CVE-2019-2839: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Succ
nvd
CVE-2019-2744MEDIUMCVSS 6.1≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2744 [MEDIUM] CVE-2019-2744: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2019-2794MEDIUMCVSS 5.3≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2794 [MEDIUM] CVE-2019-2794: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2019-2840MEDIUMCVSS 5.7≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2840 [MEDIUM] CVE-2019-2840: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2019-2793LOWCVSS 3.5≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2793 [LOW] CVE-2019-2793: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Ban
nvd