Oracle Transportation Management vulnerabilities
27 known vulnerabilities affecting oracle/transportation_management.
Total CVEs
27
CISA KEV
3
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH4MEDIUM19LOW2
Vulnerabilities
Page 2 of 2
CVE-2017-12617HIGHCVSS 8.1KEVPoCv6.3.1v6.3.2+5 more2017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-10032MEDIUMCVSS 5.4v6.3.4.1v6.3.5.1+5 more2017-08-08
CVE-2017-10032 [MEDIUM] CVE-2017-10032: Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suit
Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Access Control List). Supported versions that are affected are 6.3.4.1, 6.3.5.1, 6.3.6.1, 6.3.7.1, 6.4.0, 6.4.1 and 6.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Trans
nvd
CVE-2017-3530MEDIUMCVSS 6.1v6.2v6.3.0+10 more2017-04-24
CVE-2017-3530 [MEDIUM] CVE-2017-3530: Vulnerability in the Oracle Transportation Manager component of Oracle Supply Chain Products Suite (
Vulnerability in the Oracle Transportation Manager component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1 and 6.4.2. Easily "exploitable" vulnerability allows high privileged attacker with network access via HTTP to compromise
nvd
CVE-2016-8735CRITICALCVSS 9.8KEVPoCv6.3.0v6.3.1+6 more2017-04-06
CVE-2016-8735 [CRITICAL] CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential ty
nvd
CVE-2016-3470HIGHCVSS 7.1v6.4.12016-07-21
CVE-2016-3470 [HIGH] CVE-2016-3470: Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain P
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.4.1 allows remote authenticated users to affect confidentiality and integrity via vectors related to Install.
nvd
CVE-2016-3490LOWCVSS 3.0v6.3.0v6.3.1+8 more2016-07-21
CVE-2016-3490 [LOW] CVE-2016-3490: Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain P
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, and 6.4.1 allows remote authenticated users to affect confidentiality via vectors related to Database.
nvd
CVE-2015-3195MEDIUMCVSS 5.3v6.1v6.22015-12-06
CVE-2015-3195 [MEDIUM] CWE-200 CVE-2015-3195: The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 befo
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a decoding failure in a PKCS#7 or CMS appl
nvd
← Previous2 / 2