cbcvebase.

Oracle Transportation Management vulnerabilities

27 known vulnerabilities affecting oracle/transportation_management.

Total CVEs
27
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH4MEDIUM19LOW2

Vulnerabilities

Page 1 of 2
CVE-2020-1938P1CRITICALCVSS 9.8KEVPoCv6.3.72020-02-24
CVE-2020-1938 [CRITICAL] CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8
nvd
CVE-2017-12617P1HIGHCVSS 8.1KEVPoCv6.3.1v6.3.2+5 more2017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2016-8735P1CRITICALCVSS 9.8KEVPoCv6.3.0v6.3.1+6 more2017-04-06
CVE-2016-8735 [CRITICAL] CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8. Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential ty
nvd
CVE-2019-11358P2MEDIUMCVSS 6.1ExploitedPoCv1.4.32019-04-20
CVE-2019-11358 [MEDIUM] CWE-1321 CVE-2019-11358: jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(t jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
nvd
CVE-2020-9484P2HIGHCVSS 7.0PoCv6.3.72020-05-20
CVE-2020-9484 [HIGH] CWE-502 CVE-2020-9484: When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7. When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassN
nvd
CVE-2019-17563P3HIGHCVSS 7.5v6.3.72019-12-23
CVE-2019-17563 [HIGH] CWE-384 CVE-2019-17563: When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
nvd
CVE-2021-35616P3MEDIUMCVSS 5.4v6.4.32021-10-20
CVE-2021-35616 [MEDIUM] CVE-2021-35616: Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result i
nvd
CVE-2015-3195P3MEDIUMCVSS 5.3v6.1v6.22015-12-06
CVE-2015-3195 [MEDIUM] CWE-200 CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 befo The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS appl
nvd
CVE-2016-3470P3HIGHCVSS 7.1v6.4.12016-07-21
CVE-2016-3470 [HIGH] CVE-2016-3470: Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain P Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.4.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Install.
nvd
CVE-2019-2487P3MEDIUMCVSS 6.5v6.3.7v6.4.1+2 more2019-01-16
CVE-2019-2487 [MEDIUM] CVE-2019-2487: Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suit Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: UI Infrastructure). Supported versions that are affected are 6.3.7, 6.4.1, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful
nvd
CVE-2018-2823P3MEDIUMCVSS 6.5v6.4.32018-04-19
CVE-2018-2823 [MEDIUM] CVE-2018-2823: Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suit Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Database). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability ca
nvd
CVE-2017-3530P4MEDIUMCVSS 6.1v6.2v6.3.0+10 more2017-04-24
CVE-2017-3530 [MEDIUM] CVE-2017-3530: Vulnerability in the Oracle Transportation Manager component of Oracle Supply Chain Products Suite ( Vulnerability in the Oracle Transportation Manager component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1 and 6.4.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to compromise
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8v6.3.72020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8v6.3.72020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2022-39420P4MEDIUMCVSS 5.4v6.4.3v6.5.12022-10-18
CVE-2022-39420 [MEDIUM] CVE-2022-39420: Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Dat Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Data, Functional Security). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerab
nvd
CVE-2017-10032P4MEDIUMCVSS 5.4v6.3.4.1v6.3.5.1+5 more2017-08-08
CVE-2017-10032 [MEDIUM] CVE-2017-10032: Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suit Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Access Control List). Supported versions that are affected are 6.3.4.1, 6.3.5.1, 6.3.6.1, 6.3.7.1, 6.4.0, 6.4.1 and 6.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trans
nvd
CVE-2021-2476P4MEDIUMCVSS 5.3v6.4.32021-10-20
CVE-2021-2476 [MEDIUM] CVE-2021-2476: Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Aut Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The supported version that is affected is 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in u
nvd
CVE-2018-2662P4MEDIUMCVSS 5.4v6.2.11v6.3.1+7 more2018-01-18
CVE-2018-2662 [MEDIUM] CVE-2018-2662: Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suit Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2.11, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7 and 6.4.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportat
nvd
CVE-2019-2709P4MEDIUMCVSS 6.1v6.3.7v6.4.2+1 more2019-04-23
CVE-2019-2709 [MEDIUM] CVE-2019-2709: Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suit Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.3.7, 6.4.2 and 6.4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks require
nvd
CVE-2022-21480P4MEDIUMCVSS 6.1v6.4.3v6.5.12022-04-19
CVE-2022-21480 [MEDIUM] CVE-2022-21480: Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Use Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: User Interface). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks require human interaction
nvd
Oracle Transportation Management vulnerabilities | cvebase