VendorsOraclebanking_enterprise_default_management2.7.1
Vulnerabilities

Oracle Banking Enterprise Default Management 2.7.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2020-13936
Velocity Sandbox Bypass
Published 2021-03-10 · Modified
9.0EPSS 0.227
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Published 2019-11-08 · Modified
6.5EPSS 0.022
CVE-2020-9281
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
Published 2020-03-07 · Modified
6.1EPSS 0.043
CVE-2021-35043
OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). This was demonstrated by a javascript: URL with &#00058 as the replacement for the : character.
Published 2021-07-19 · Modified
6.1EPSS 0.015
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2021-29425
Possible limited path traversal vulnerabily in Apache Commons IO
Published 2021-04-13 · Modified
5.8EPSS 0.099