Oracle Utilities Framework vulnerabilities
38 known vulnerabilities affecting oracle/utilities_framework.
Total CVEs
38
CISA KEV
2
actively exploited
Public exploits
5
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH21MEDIUM10LOW1
Vulnerabilities
Page 2 of 2
CVE-2021-31684HIGHCVSS 7.5v4.4.0.0.0v4.4.0.2.0+1 more2021-06-01
CVE-2021-31684 [HIGH] CWE-787 CVE-2021-31684: A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
nvd
CVE-2021-27568MEDIUMCVSS 5.9v4.4.0.0.0v4.4.0.2.0+1 more2021-02-23
CVE-2021-27568 [MEDIUM] CWE-754 CVE-2021-27568: An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. A
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
nvd
CVE-2020-14756CRITICALCVSS 9.8≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+4 more2021-01-20
CVE-2020-14756 [CRITICAL] CVE-2020-14756: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Component
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core Components). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle Coherence. Successful attacks of
nvd
CVE-2020-28052HIGHCVSS 8.1v4.3.0.6.0v4.4.0.0.0+2 more2020-12-18
CVE-2020-28052 [HIGH] CVE-2020-28052: An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.chec
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
nvd
CVE-2020-25649HIGHCVSS 7.5v4.3.0.5.0v4.3.0.6.0+3 more2020-12-03
CVE-2020-25649 [HIGH] CWE-611 CVE-2020-25649: A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured prope
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
nvd
CVE-2020-14895MEDIUMCVSS 5.4≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-10-21
CVE-2020-14895 [MEDIUM] CVE-2020-14895: Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component:
Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: System Wide). Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and 4.4.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilitie
nvd
CVE-2020-11979HIGHCVSS 7.5v4.3.0.5.0v4.3.0.6.0+2 more2020-10-01
CVE-2020-11979 [HIGH] CWE-379 CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it crea
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modifi
nvd
CVE-2020-1945MEDIUMCVSS 6.3≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-05-14
CVE-2020-1945 [MEDIUM] CWE-668 CVE-2020-1945: Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source file
nvd
CVE-2020-10683CRITICALCVSS 9.8≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-05-01
CVE-2020-10683 [CRITICAL] CWE-611 CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, whi
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
nvd
CVE-2020-9488LOWCVSS 3.7≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+4 more2020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2020-2555CRITICALCVSS 9.8KEVPoC≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+3 more2020-01-15
CVE-2020-2555 [CRITICAL] CWE-502 CVE-2020-2555: Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheS
Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Caching,CacheStore,Invocation). Supported versions that are affected are 3.7.1.0, 12.1.3.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks o
nvd
CVE-2019-10219MEDIUMCVSS 6.1≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+4 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-17495CRITICALCVSS 9.8v4.3.0.6.0v4.4.0.0.0+1 more2019-10-10
CVE-2019-17495 [CRITICAL] CWE-352 CVE-2019-17495: A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote s
nvd
CVE-2019-10086HIGHCVSS 7.3≥ 4.3.0.1.0, ≤ 4.3.0.6.0v4.2.0.2.0+4 more2019-08-20
CVE-2019-10086 [HIGH] CWE-502 CVE-2019-10086: In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressi
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
nvd
CVE-2019-10173CRITICALCVSS 9.8≥ 4.3.0.1.0, ≤ 4.3.0.6.0v2.2.0.0.0+3 more2019-07-23
CVE-2019-10173 [CRITICAL] CVE-2019-10173: It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous de
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
nvd
CVE-2018-1000632HIGHCVSS 7.5≥ 4.3.0.2.0, ≤ 4.3.0.6.0v2.2.0+4 more2018-08-20
CVE-2018-1000632 [HIGH] CWE-91 CVE-2018-1000632: dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Elemen
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML document. This vulnerability app
nvd
CVE-2018-8088CRITICALCVSS 9.8v4.2.0.2.0v4.2.0.3.0+6 more2018-03-20
CVE-2018-8088 [CRITICAL] CVE-2018-8088: org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote att
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
nvd
CVE-2015-9251MEDIUMCVSS 6.1≥ 4.3.0.1, ≤ 4.3.0.42018-01-18
CVE-2015-9251 [MEDIUM] CWE-79 CVE-2015-9251: jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax req
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
nvd
← Previous2 / 2