cbcvebase.

Oracle Primavera Unifier vulnerabilities

95 known vulnerabilities affecting oracle/primavera_unifier.

Total CVEs
95
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
8
Severity breakdown
CRITICAL20HIGH35MEDIUM38LOW2

Vulnerabilities

Page 4 of 5
CVE-2020-11111P3HIGHCVSS 8.8≥ 17.7, ≤ 17.12v16.1+3 more2020-03-31
CVE-2020-11111 [HIGH] CWE-502 CVE-2020-11111: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
nvd
CVE-2016-7103P3MEDIUMCVSS 6.1≥ 16.0, ≤ 16.2≥ 17.0, ≤ 17.12.4+1 more2017-03-15
CVE-2016-7103 [MEDIUM] CWE-79 CVE-2016-7103: Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function.
nvd
CVE-2020-36518P3HIGHCVSS 7.5≥ 17.0, ≤ 17.12v18.0+3 more2022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2020-13956P3MEDIUMCVSS 5.3≥ 17.7, ≤ 17.12v16.1+4 more2020-12-02
CVE-2020-13956 [MEDIUM] CVE-2020-13956: Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority co Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
nvd
CVE-2018-2966P3HIGHCVSS 7.4v16.1v16.2+21 more2018-07-18
CVE-2018-2966 [HIGH] CVE-2018-2966: Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subco Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported versions that are affected are 16.x, 17.x and 18.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person
nvd
CVE-2020-28500P3MEDIUMCVSS 5.3≥ 17.7, ≤ 17.12v18.8+2 more2021-02-15
CVE-2020-28500 [MEDIUM] CVE-2020-28500: Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
nvd
CVE-2021-29425P4MEDIUMCVSS 4.8≥ 17.7, ≤ 17.12v18.8+3 more2021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2016-4055P4MEDIUMCVSS 6.5≥ 16.0, ≤ 18.8.42017-01-23
CVE-2016-4055 [MEDIUM] CWE-400 CVE-2016-4055: The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cau The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."
nvd
CVE-2018-8032P4MEDIUMCVSS 6.1≥ 17.7, ≤ 17.12v16.1+3 more2018-08-02
CVE-2018-8032 [MEDIUM] CWE-79 CVE-2018-8032: Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
nvd
CVE-2020-1945P4MEDIUMCVSS 6.3≥ 17.7, ≤ 17.12v16.1+3 more2020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2020-35460P4MEDIUMCVSS 5.3≥ 17.7, ≤ 17.12v16.1+4 more2020-12-14
CVE-2020-35460 [MEDIUM] CWE-22 CVE-2020-35460: common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip st common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
nvd
CVE-2018-2968P4MEDIUMCVSS 6.5v16.1v16.2+21 more2018-07-18
CVE-2018-2968 [MEDIUM] CVE-2018-2968: Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subco Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported versions that are affected are 16.x, 17.x and 18.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a pers
nvd
CVE-2020-14618P4MEDIUMCVSS 5.9fixed in 20.62020-07-15
CVE-2020-14618 [MEDIUM] CVE-2020-14618: Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Mo Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Mobile App). The supported version that is affected is Prior to 20.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera Unifier. Successful attacks require human interaction from a person ot
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1≥ 17.7, ≤ 17.12v18.8+3 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2017-3501P4MEDIUMCVSS 6.1v9.13v9.14+4 more2017-04-24
CVE-2017-3501 [MEDIUM] CVE-2017-3501: Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: P Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.0, 10.1, 15.1 and 15.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interacti
nvd
CVE-2018-3148P4MEDIUMCVSS 6.1≥ 17.1, ≤ 17.12≥ 18.1, ≤ 18.8+4 more2018-10-17
CVE-2018-3148 [MEDIUM] CVE-2018-3148: Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subco Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supported versions that are affected are 15.1, 15.2, 16.1, 16.2, 17.1-17.12 and 18.1-18.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks re
nvd
CVE-2020-14617P4MEDIUMCVSS 5.7fixed in 20.6≥ 17.7, ≤ 17.12+4 more2020-07-15
CVE-2020-14617 [MEDIUM] CVE-2020-14617: Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Pl Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App). Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and 19.12; Mobile App: Prior to 20.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Primavera Unifier. Suc
nvd
CVE-2019-12415P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v16.1+3 more2019-10-23
CVE-2019-12415 [MEDIUM] CWE-611 CVE-2019-12415: In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Ex In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
nvd
CVE-2021-31811P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+2 more2021-06-12
CVE-2021-31811 [MEDIUM] CWE-789 CVE-2021-31811: In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading th In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
nvd
CVE-2020-17521P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v16.1+4 more2020-12-07
CVE-2020-17521 [MEDIUM] CVE-2020-17521: Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this f Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is potentially not secure on some operating systems in some contexts. Users not using the extension methods mentioned in the advisory are not affected,
nvd
Oracle Primavera Unifier vulnerabilities | cvebase