Oracle Retail Back Office vulnerabilities
22 known vulnerabilities affecting oracle/retail_back_office.
Total CVEs
22
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL3HIGH7MEDIUM12
Vulnerabilities
Page 2 of 2
CVE-2021-35043P4MEDIUMCVSS 6.1v14.0v14.12021-07-19
CVE-2021-35043 [MEDIUM] CWE-79 CVE-2021-35043: OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XH
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with : as the replacement for the : character.
nvd
CVE-2021-36373P4MEDIUMCVSS 5.5v14.0v14.12021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd
← Previous2 / 2