Oracle Timesten In-Memory Database vulnerabilities

27 known vulnerabilities affecting oracle/timesten_in-memory_database.

Total CVEs
27
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH10MEDIUM12

Vulnerabilities

Page 1 of 2
CVE-2021-36221MEDIUMCVSS 5.9fixed in 21.1.1.1.02021-08-08
CVE-2021-36221 [MEDIUM] CWE-362 CVE-2021-36221: Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
nvd
CVE-2021-29923HIGHCVSS 7.5fixed in 21.1.1.1.02021-08-07
CVE-2021-29923 [HIGH] CVE-2021-29923: Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP addre Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
nvd
CVE-2021-2351HIGHCVSS 7.5fixed in 21.1.1.1.0v21.1.1.1.02021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2021-34558MEDIUMCVSS 6.5fixed in 21.1.1.1.02021-07-15
CVE-2021-34558 [MEDIUM] CWE-295 CVE-2021-34558: The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
nvd
CVE-2021-36373MEDIUMCVSS 5.5fixed in 11.2.2.8.272021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd
CVE-2021-36374MEDIUMCVSS 5.5fixed in 11.2.2.8.272021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2020-11979HIGHCVSS 7.5fixed in 11.2.2.8.272020-10-01
CVE-2020-11979 [HIGH] CWE-379 CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it crea As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modifi
nvd
CVE-2020-7712HIGHCVSS 7.2fixed in 21.1.1.1.02020-08-30
CVE-2020-7712 [HIGH] CWE-78 CVE-2020-7712: This affects the package json before 10.0.0. It is possible to inject arbritary commands using the p This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
nvd
CVE-2020-1945MEDIUMCVSS 6.3fixed in 11.2.2.8.27v11.2.2.8.492020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2019-10219MEDIUMCVSS 6.1fixed in 11.2.2.8.27≥ 21.0.0, < 21.1.1.1.02019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-1010239HIGHCVSS 7.5fixed in 18.1.3.1.02019-07-19
CVE-2019-1010239 [HIGH] CWE-476 CVE-2019-1010239: DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. T DaveGamble/cJSON cJSON 1.7.8 is affected by: Improper Check for Unusual or Exceptional Conditions. The impact is: Null dereference, so attack can cause denial of service. The component is: cJSON_GetObjectItemCaseSensitive() function. The attack vector is: crafted json file. The fixed version is: 1.7.9 and later.
nvd
CVE-2019-0201MEDIUMCVSS 5.9fixed in 18.1.3.1.02019-05-23
CVE-2019-0201 [MEDIUM] CWE-862 CVE-2019-0201: An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s g An issue is present in Apache ZooKeeper 1.0.0 to 3.4.13 and 3.5.0-alpha to 3.5.4-beta. ZooKeeper’s getACL() command doesn’t check any permission when retrieves the ACLs of the requested node and returns all information contained in the ACL Id field as plaintext string. DigestAuthenticationProvider overloads the Id field with the hash value that is use
nvd
CVE-2019-11834CRITICALCVSS 9.8fixed in 18.1.3.1.02019-05-09
CVE-2019-11834 [CRITICAL] CWE-125 CVE-2019-11834: cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal. cJSON before 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
nvd
CVE-2019-11835CRITICALCVSS 9.8fixed in 18.1.3.1.02019-05-09
CVE-2019-11835 [CRITICAL] CWE-125 CVE-2019-11835: cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments. cJSON before 1.7.11 allows out-of-bounds access, related to multiline comments.
nvd
CVE-2018-15769HIGHCVSS 7.5fixed in 18.1.4.1.02018-11-16
CVE-2018-15769 [HIGH] CVE-2018-15769: RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6 RSA BSAFE Micro Edition Suite versions prior to 4.0.11 (in 4.0.x series) and versions prior to 4.1.6.2 (in 4.1.x series) contain a key management error issue. A malicious TLS server could potentially cause a Denial Of Service (DoS) on TLS clients during the handshake when a very large prime value is sent to the TLS client, and an Ephemeral or Anonymous Diffie
nvd
CVE-2018-11058CRITICALCVSS 9.8fixed in 18.1.4.1.02018-09-14
CVE-2018-11058 [CRITICAL] CWE-125 CVE-2018-11058: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), an RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.
nvd
CVE-2018-11054HIGHCVSS 7.5≤ 18.1.4.1.02018-08-31
CVE-2018-11054 [HIGH] CWE-190 CVE-2018-11054: RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote a RSA BSAFE Micro Edition Suite, version 4.1.6, contains an integer overflow vulnerability. A remote attacker could use maliciously constructed ASN.1 data to potentially cause a Denial Of Service.
nvd
CVE-2018-11056MEDIUMCVSS 6.5fixed in 18.1.4.1.02018-08-31
CVE-2018-11056 [MEDIUM] CWE-400 CVE-2018-11056: RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition ver RSA BSAFE Micro Edition Suite, prior to 4.1.6.1 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition versions prior to 4.0.5.3 (in 4.0.x) contain an Uncontrolled Resource Consumption ('Resource Exhaustion') vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would exhaust the stack, potentially caus
nvd
CVE-2018-11055MEDIUMCVSS 5.5fixed in 18.1.4.1.02018-08-31
CVE-2018-11055 [MEDIUM] CWE-404 CVE-2018-11055: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x), contains an Improper Clearing of Heap Memory Before Release ('Heap Inspection') vulnerability. Decoded PKCS #12 data in heap memory is not zeroized by MES before releasing the memory internally and a malicious local user could gain access to the unauth
nvd
CVE-2018-11057MEDIUMCVSS 5.9fixed in 18.1.4.1.02018-08-31
CVE-2018-11057 [MEDIUM] CWE-327 CVE-2018-11057: RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) c RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6.1 (in 4.1.x) contains a Covert Timing Channel vulnerability during RSA decryption, also known as a Bleichenbacher attack on RSA decryption. A remote attacker may be able to recover a RSA key.
nvd