Oracle Primavera Unifier vulnerabilities
95 known vulnerabilities affecting oracle/primavera_unifier.
Total CVEs
95
CISA KEV
1
actively exploited
Public exploits
8
Exploited in wild
8
Severity breakdown
CRITICAL20HIGH35MEDIUM38LOW2
Vulnerabilities
Page 5 of 5
CVE-2021-27906P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+2 more2021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-27807P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+2 more2021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2021-36374P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+2 more2021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2018-2965P4MEDIUMCVSS 6.1v16.1v16.2+2 more2018-07-18
CVE-2018-2965 [MEDIUM] CVE-2018-2965: Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subco
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The supported version that is affected is 16.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require human interaction from a person other than
nvd
CVE-2021-36373P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+2 more2021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd
CVE-2021-28657P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+2 more2021-03-31
CVE-2021-28657 [MEDIUM] CWE-835 CVE-2021-28657: A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and inclu
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika users should upgrade to 1.26 or later.
nvd
CVE-2020-9489P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v16.1+3 more2020-04-27
CVE-2020-9489 [MEDIUM] CWE-835 CVE-2020-9489: A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or c
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS7BDATParser, OneNoteParser and ImageParser. Apache Tika users should upgrade to 1.24.1 or later. The vulnerabilities in the MP4Parser
nvd
CVE-2022-25169P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+3 more2022-05-16
CVE-2022-25169 [MEDIUM] CWE-770 CVE-2022-25169: The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amoun
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully crafted files.
nvd
CVE-2020-9488P4LOWCVSS 3.7v18.8v19.122020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2022-30126P4MEDIUMCVSS 5.5≥ 17.7, ≤ 17.12v18.8+3 more2022-05-16
CVE-2022-30126 [MEDIUM] CVE-2022-30126: In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingCont
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler, which is a non-standard handler. This is fixed in 1.28.2 and 2.4.0
nvd
CVE-2017-10150P4MEDIUMCVSS 4.3v9.13v9.14+6 more2017-08-08
CVE-2017-10150 [MEDIUM] CVE-2017-10150: Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: P
Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vuln
nvd
CVE-2018-2967P4MEDIUMCVSS 5.3v16.1v16.2+21 more2018-07-18
CVE-2018-2967 [MEDIUM] CVE-2018-2967: Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subco
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported versions that are affected are 16.x, 17.x and 18.x. Easily exploitable vulnerability allows physical access to compromise Primavera Unifier. While the vulnerability is in Primavera Unifier, attacks may significantly impact additional p
nvd
CVE-2018-2969P4MEDIUMCVSS 4.3v16.1v16.2+2 more2018-07-18
CVE-2018-2969 [MEDIUM] CVE-2018-2969: Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subco
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The supported version that is affected is 16.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks of this vulnerability can result in unauthorized rea
nvd
CVE-2017-10149P4MEDIUMCVSS 4.8v9.13v9.14+6 more2017-08-08
CVE-2017-10149 [MEDIUM] CVE-2017-10149: Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: P
Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions that are affected are 9.13, 9.14, 10.1, 10.2, 15.1, 15.2, 16.1 and 16.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Unifier. Successful attacks require hum
nvd
CVE-2020-8908P4LOWCVSS 3.3≥ 17.7, ≤ 17.12v18.8+3 more2020-12-10
CVE-2020-8908 [LOW] CWE-378 CVE-2020-8908: A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with a
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potentially access data in a temporary directory created by the Guava API com.google.common.io.Files.createTempDir(). By default, on unix-like systems, the created directory is world-readable (readable by an attacker with access to
nvd
← Previous5 / 5