Oracle Flexcube Universal Banking vulnerabilities
95 known vulnerabilities affecting oracle/flexcube_universal_banking.
Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH20MEDIUM71LOW4
Vulnerabilities
Page 3 of 5
CVE-2023-22118P4MEDIUMCVSS 6.5≥ 14.0.0, ≤ 14.3.0≥ 14.5.0, ≤ 14.7.0+2 more2023-10-17
CVE-2023-22118 [MEDIUM] CVE-2023-22118: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Succe
nvd
CVE-2021-41973P4MEDIUMCVSS 6.5≥ 14.0, ≤ 14.3v14.52021-11-01
CVE-2021-41973 [MEDIUM] CWE-835 CVE-2021-41973: In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to
In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is more data than expected. Please update MINA to 2.1.5 or greater.
nvd
CVE-2018-2975P4MEDIUMCVSS 5.3v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2975 [MEDIUM] CVE-2018-2975: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via H
nvd
CVE-2018-2982P4MEDIUMCVSS 5.3v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2982 [MEDIUM] CVE-2018-2982: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via
nvd
CVE-2018-2899P4MEDIUMCVSS 6.1v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2899 [MEDIUM] CVE-2018-2899: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via H
nvd
CVE-2019-2840P4MEDIUMCVSS 5.7≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2840 [MEDIUM] CVE-2019-2840: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2022-21472P4MEDIUMCVSS 5.9≥ 14.0.0, ≤ 14.3.0v12.4.0+1 more2022-04-19
CVE-2022-21472 [MEDIUM] CVE-2022-21472: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.4, 14.0-14.3 and 14.5. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful att
nvd
CVE-2018-2980P4MEDIUMCVSS 5.4v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2980 [MEDIUM] CVE-2018-2980: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT
nvd
CVE-2023-22119P4MEDIUMCVSS 5.9≥ 14.0.0, ≤ 14.3.0≥ 14.5.0, ≤ 14.7.0+2 more2023-10-17
CVE-2023-22119 [MEDIUM] CVE-2023-22119: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Suc
nvd
CVE-2016-8307P4MEDIUMCVSS 5.3v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8307 [MEDIUM] CWE-284 CVE-2016-8307: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE
nvd
CVE-2018-2981P4MEDIUMCVSS 5.4v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-2981 [MEDIUM] CVE-2018-2981: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT
nvd
CVE-2017-10072P4MEDIUMCVSS 5.4v11.3.0v11.4.0+6 more2017-08-08
CVE-2017-10072 [MEDIUM] CVE-2017-10072: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: All Modules). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle F
nvd
CVE-2019-2794P4MEDIUMCVSS 5.3≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2794 [MEDIUM] CVE-2019-2794: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2018-2614P4MEDIUMCVSS 5.3v11.3.0v11.4.0+7 more2018-01-18
CVE-2018-2614 [MEDIUM] CVE-2018-2614: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0 and 12.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromi
nvd
CVE-2016-5622P4MEDIUMCVSS 6.1v11.3.0v11.4.0+5 more2016-10-25
CVE-2016-5622 [MEDIUM] CWE-284 CVE-2016-5622: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Ser
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote attackers to affect confidentiality and integrity via vectors related to INFRA.
nvd
CVE-2018-2748P4MEDIUMCVSS 6.1v11.3.0v11.4.0+8 more2018-04-19
CVE-2018-2748 [MEDIUM] CVE-2018-2748: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successf
nvd
CVE-2017-10098P4MEDIUMCVSS 5.4v11.3.0v11.4.0+6 more2017-08-08
CVE-2017-10098 [MEDIUM] CWE-269 CVE-2017-10098: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromi
nvd
CVE-2018-2630P4MEDIUMCVSS 5.4v11.5.0v11.6.0+1 more2018-01-18
CVE-2018-2630 [MEDIUM] CVE-2018-2630: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Security Management System). Supported versions that are affected are 11.5.0, 11.6.0 and 11.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.
nvd
CVE-2019-2839P4MEDIUMCVSS 5.3≥ 12.1.0, ≤ 12.4.0≥ 14.0.0, ≤ 14.2.02019-07-23
CVE-2019-2839 [MEDIUM] CVE-2019-2839: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.1.0-12.4.0 and 14.0.0-14.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Succ
nvd
CVE-2019-2790P4MEDIUMCVSS 5.4≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2790 [MEDIUM] CVE-2019-2790: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd