VendorsOraclebanking_extensibility_workbench14.3.0
Vulnerabilities

Oracle Banking Extensibility Workbench 14.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-8174
napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.
Published 2020-07-24 · Modified
9.3EPSS 0.076
CVE-2019-10744
Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Published 2019-07-25 · Modified
9.1EPSS 0.050
CVE-2020-10531
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
Published 2020-03-12 · Modified
8.8EPSS 0.027
CVE-2020-28052
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Published 2020-12-18 · Modified
8.1EPSS 0.072
CVE-2020-11080
Denial of service in nghttp2
Published 2020-06-03 · Modified
7.5EPSS 0.053
CVE-2020-8172
TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.
Published 2020-06-08 · Modified
7.4EPSS 0.061
CVE-2020-8203
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Published 2020-07-15 · Modified
7.4EPSS 0.052
CVE-2021-23337
Command Injection
Published 2021-02-15 · Modified
7.2EPSS 0.213
CVE-2020-28500
Regular Expression Denial of Service (ReDoS)
Published 2021-02-15 · Modified
5.3EPSS 0.073