Oracle Flexcube Universal Banking vulnerabilities
95 known vulnerabilities affecting oracle/flexcube_universal_banking.
Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH20MEDIUM71LOW4
Vulnerabilities
Page 2 of 5
CVE-2020-2699P3HIGHCVSS 7.1≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2699 [HIGH] CVE-2020-2699: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful at
nvd
CVE-2018-2747P3MEDIUMCVSS 6.5v11.3.0v11.4.0+8 more2018-04-19
CVE-2018-2747 [MEDIUM] CVE-2018-2747: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2017-10084P3MEDIUMCVSS 6.5v11.3.0v11.4.0+6 more2017-08-08
CVE-2017-10084 [MEDIUM] CWE-200 CVE-2017-10084: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Report Generator). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compro
nvd
CVE-2017-3534P3MEDIUMCVSS 6.5v12.0.1v12.0.2+4 more2017-04-24
CVE-2017-3534 [MEDIUM] CVE-2017-3534: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Unive
nvd
CVE-2017-3485P3MEDIUMCVSS 6.8v11.3.0v11.4.0+6 more2017-04-24
CVE-2017-3485 [MEDIUM] CVE-2017-3485: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracl
nvd
CVE-2016-8311P3MEDIUMCVSS 6.5v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8311 [MEDIUM] CWE-284 CVE-2016-8311: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE U
nvd
CVE-2020-14887P3MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.4.0v12.3.02020-10-21
CVE-2020-14887 [MEDIUM] CVE-2020-14887: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3.0 and 14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attac
nvd
CVE-2020-2684P3MEDIUMCVSS 6.5≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2684 [MEDIUM] CVE-2020-2684: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2018-2974P3MEDIUMCVSS 6.3v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2974 [MEDIUM] CVE-2018-2974: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT
nvd
CVE-2022-21576P3MEDIUMCVSS 6.4≥ 14.0.0, ≤ 14.3.0v12.3.0+2 more2022-07-19
CVE-2022-21576 [MEDIUM] CVE-2022-21576: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successf
nvd
CVE-2022-23437P3MEDIUMCVSS 6.5v12.4.02022-01-24
CVE-2022-23437 [MEDIUM] CWE-835 CVE-2022-23437: There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially c
There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged duration. This vulnerability is present within XercesJ version 2.12.1 and the previous versions.
nvd
CVE-2021-30129P3MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.3.0v14.52021-07-12
CVE-2021-30129 [MEDIUM] CWE-772 CVE-2021-30129: A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing a
A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and later versions. It was addressed in Apache Mina SSHD 2.7.0
nvd
CVE-2022-21544P3HIGHCVSS 7.1≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21544 [HIGH] CVE-2022-21544: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2022-21579P3MEDIUMCVSS 6.4≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21579 [MEDIUM] CVE-2022-21579: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2022-21577P3MEDIUMCVSS 6.4≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21577 [MEDIUM] CVE-2022-21577: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2021-2323P3MEDIUMCVSS 5.9≥ 14.0.0, ≤ 14.4.0v12.3.0+1 more2021-07-21
CVE-2021-2323 [MEDIUM] CVE-2021-2323: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Flex-Branch). Supported versions that are affected are 12.3, 12.4, 14.0-14.4 and . Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attac
nvd
CVE-2018-2979P3MEDIUMCVSS 6.5v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2979 [MEDIUM] CVE-2018-2979: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT
nvd
CVE-2022-21428P3MEDIUMCVSS 6.7≥ 12.1.0, ≤ 12.4≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21428 [MEDIUM] CVE-2022-21428: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2022-21578P3MEDIUMCVSS 6.7≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.0+1 more2022-07-19
CVE-2022-21578 [MEDIUM] CVE-2022-21578: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.1-12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2016-8299P3MEDIUMCVSS 6.3v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8299 [MEDIUM] CWE-284 CVE-2016-8299: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE U
nvd