Oracle Flexcube Universal Banking vulnerabilities
95 known vulnerabilities affecting oracle/flexcube_universal_banking.
Total CVEs
95
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH20MEDIUM71LOW4
Vulnerabilities
Page 4 of 5
CVE-2020-2683P4MEDIUMCVSS 5.4≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2683 [MEDIUM] CVE-2020-2683: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2017-10083P4MEDIUMCVSS 6.1v11.3.0v11.4.0+6 more2017-08-08
CVE-2017-10083 [MEDIUM] CVE-2017-10083: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Orac
nvd
CVE-2016-8303P4MEDIUMCVSS 6.1v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8303 [MEDIUM] CWE-254 CVE-2016-8303: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE
nvd
CVE-2017-3314P4MEDIUMCVSS 6.1v12.0.0v12.1.0+1 more2017-01-27
CVE-2017-3314 [MEDIUM] CVE-2017-3314: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.0, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful attacks re
nvd
CVE-2019-2744P4MEDIUMCVSS 6.1≥ 12.0.1, ≤ 12.0.3≥ 12.1.0, ≤ 12.4.0+1 more2019-07-23
CVE-2019-2744 [MEDIUM] CVE-2019-2744: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.1-12.0.3, 12.1.0-12.4.0 and 14.0.0-14.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal
nvd
CVE-2016-5620P4MEDIUMCVSS 5.4v11.3.0v11.4.0+5 more2016-10-25
CVE-2016-5620 [MEDIUM] CVE-2016-5620: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Ser
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA, a different vulnerability than CVE-2016-5619.
nvd
CVE-2020-2685P4MEDIUMCVSS 5.4≥ 12.0.1, ≤ 12.4.0≥ 14.0.0, ≤ 14.3.02020-01-15
CVE-2020-2685 [MEDIUM] CVE-2020-2685: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.0.1-12.4.0 and 14.0.0-14.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successful
nvd
CVE-2023-22117P4MEDIUMCVSS 5.4≥ 14.0.0, ≤ 14.3.0≥ 14.5.0, ≤ 14.7.0+2 more2023-10-17
CVE-2023-22117 [MEDIUM] CVE-2023-22117: Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applicat
Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 12.3, 12.4, 14.0-14.3 and 14.5-14.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Succe
nvd
CVE-2021-31811P4MEDIUMCVSS 5.5≥ 14.0.0, ≤ 14.3.0v14.52021-06-12
CVE-2021-31811 [MEDIUM] CWE-789 CVE-2021-31811: In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading th
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
nvd
CVE-2016-5502P4MEDIUMCVSS 5.4v11.3.0v11.4.0+3 more2016-10-25
CVE-2016-5502 [MEDIUM] CWE-284 CVE-2016-5502: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Ser
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to INFRA.
nvd
CVE-2018-3019P4MEDIUMCVSS 5.4v11.3.0v11.4.0+9 more2018-07-18
CVE-2018-3019 [MEDIUM] CVE-2018-3019: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0, 12.3.0, 12.4.0, 14.0.0 and 14.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HT
nvd
CVE-2018-2749P4MEDIUMCVSS 5.4v11.3.0v11.4.0+8 more2018-04-19
CVE-2018-2749 [MEDIUM] CVE-2018-2749: Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applica
Vulnerability in the Oracle Banking Corporate Lending component of Oracle Financial Services Applications (subcomponent: Core module). Supported versions that are affected are 12.3.0, 12.4.0, 12.5.0 and 14.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending. Successfu
nvd
CVE-2017-3482P4MEDIUMCVSS 5.4v12.0.0v12.0.1+5 more2017-04-24
CVE-2017-3482 [MEDIUM] CVE-2017-3482: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily "exploitable" vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCU
nvd
CVE-2016-8304P4MEDIUMCVSS 5.4v11.3.0v11.4.0+5 more2017-01-27
CVE-2016-8304 [MEDIUM] CWE-284 CVE-2016-8304: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE U
nvd
CVE-2021-27906P4MEDIUMCVSS 5.5≥ 14.0.0, ≤ 14.3.0v14.5.02021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27807P4MEDIUMCVSS 5.5≥ 14.0.0, ≤ 14.3.0v14.5.02021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2017-10073P4MEDIUMCVSS 5.4v11.3.0v11.4.0+6 more2017-08-08
CVE-2017-10073 [MEDIUM] CVE-2017-10073: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracl
nvd
CVE-2016-5594P4MEDIUMCVSS 5.0v11.3.0v11.4.0+3 more2016-10-25
CVE-2016-5594 [MEDIUM] CWE-284 CVE-2016-5594: Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Ser
Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, and 12.0.1 through 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to INFRA.
nvd
CVE-2017-3480P4MEDIUMCVSS 4.7v11.3.0v11.4.0+1 more2017-04-24
CVE-2017-3480 [MEDIUM] CVE-2017-3480: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0 and 12.0.1. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking. Successfu
nvd
CVE-2017-3535P4MEDIUMCVSS 4.7v11.3.0v11.4.0+3 more2017-04-24
CVE-2017-3535 [MEDIUM] CVE-2017-3535: Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applic
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and 12.0.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Ba
nvd