cbcvebase.

Oracle Utilities Framework vulnerabilities

38 known vulnerabilities affecting oracle/utilities_framework.

Total CVEs
38
CISA KEV
2
actively exploited
Public exploits
8
Exploited in wild
6
Severity breakdown
CRITICAL6HIGH21MEDIUM10LOW1

Vulnerabilities

Page 2 of 2
CVE-2019-17495P3CRITICALCVSS 9.8v4.3.0.6.0v4.4.0.0.0+1 more2019-10-10
CVE-2019-17495 [CRITICAL] CWE-352 CVE-2019-17495: A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote s
nvd
CVE-2020-28052P3HIGHCVSS 8.1v4.3.0.6.0v4.4.0.0.0+2 more2020-12-18
CVE-2020-28052 [HIGH] CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.chec An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
nvd
CVE-2021-39150P3HIGHCVSS 8.5v4.2.0.2.0v4.2.0.3.0+5 more2021-08-23
CVE-2021-39150 [HIGH] CWE-502 CVE-2021-39150: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed input stream with a Java runtime version 14 to 8. No user is affected, who followed the recommendation to
nvd
CVE-2020-10683P3CRITICALCVSS 9.8≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2020-11979P3HIGHCVSS 7.5v4.3.0.5.0v4.3.0.6.0+2 more2020-10-01
CVE-2020-11979 [HIGH] CWE-379 CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it crea As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modifi
nvd
CVE-2018-1000632P3HIGHCVSS 7.5≥ 4.3.0.2.0, ≤ 4.3.0.6.0v2.2.0+4 more2018-08-20
CVE-2018-1000632 [HIGH] CWE-91 CVE-2018-1000632: dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Elemen dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability app
nvd
CVE-2021-2351P3HIGHCVSS 7.5≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.3.0+3 more2021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd
CVE-2020-36518P3HIGHCVSS 7.5v4.3.0.5.0v4.3.0.6.0+4 more2022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2021-39140P3MEDIUMCVSS 6.3v4.2.0.2.0v4.2.0.3.0+5 more2021-08-23
CVE-2021-39140 [MEDIUM] CWE-502 CVE-2021-39140: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected,
nvd
CVE-2021-31684P3HIGHCVSS 7.5v4.4.0.0.0v4.4.0.2.0+1 more2021-06-01
CVE-2021-31684 [HIGH] CWE-787 CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
nvd
CVE-2020-1945P4MEDIUMCVSS 6.3≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2021-27568P4MEDIUMCVSS 5.9v4.4.0.0.0v4.4.0.2.0+1 more2021-02-23
CVE-2021-27568 [MEDIUM] CWE-754 CVE-2021-27568: An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. A An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
nvd
CVE-2020-14895P4MEDIUMCVSS 5.4≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-10-21
CVE-2020-14895 [MEDIUM] CVE-2020-14895: Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and 4.4.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilitie
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+4 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2026-21924P4MEDIUMCVSS 5.4v4.3.0.3.0v4.5.0.0.0+5 more2026-01-20
CVE-2026-21924 [MEDIUM] CVE-2026-21924: Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications Vulnerability in the Oracle Utilities Application Framework product of Oracle Utilities Applications (component: General). Supported versions that are affected are 4.4.0.3.0, 4.5.0.0.0, 4.5.0.1.1, 4.5.0.1.3, 4.5.0.2.0, 25.4 and 25.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities
nvd
CVE-2021-36374P4MEDIUMCVSS 5.5≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+4 more2021-07-14
CVE-2021-36374 [MEDIUM] CWE-130 CVE-2021-36374: When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Commonly used derived formats from ZIP archives are for instance JAR files and many office files. Apac
nvd
CVE-2021-36373P4MEDIUMCVSS 5.5≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+4 more2021-07-14
CVE-2021-36373 [MEDIUM] CWE-130 CVE-2021-36373: When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amoun When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally leads to an out of memory error, even for small inputs. This can be used to disrupt builds using Apache Ant. Apache Ant prior to 1.9.16 and 1.10.11 were affected.
nvd
CVE-2020-9488P4LOWCVSS 3.7≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
Oracle Utilities Framework vulnerabilities | cvebase