VendorsOraclebanking_supply_chain_finance14.3.0
Vulnerabilities

Oracle Banking Supply Chain Finance 14.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-5413
Kryo Configuration Allows Code Execution with Unknown "Serialization Gadgets"
Published 2020-07-31 · Modified
9.8EPSS 0.044
CVE-2020-24750
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Published 2020-09-17 · Modified
8.1EPSS 0.073
CVE-2020-28052
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Published 2020-12-18 · Modified
8.1EPSS 0.072
CVE-2020-8203
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Published 2020-07-15 · Modified
7.4EPSS 0.052
CVE-2021-23337
Command Injection
Published 2021-02-15 · Modified
7.2EPSS 0.213
CVE-2021-31811
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading a tiny file
Published 2021-06-12 · Modified
5.5EPSS 0.034
CVE-2021-27906
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file
Published 2021-03-19 · Modified
5.5EPSS 0.033
CVE-2021-31812
A carefully crafted PDF file can trigger an infinite loop while loading the file
Published 2021-06-12 · Modified
5.5EPSS 0.031
CVE-2020-28500
Regular Expression Denial of Service (ReDoS)
Published 2021-02-15 · Modified
5.3EPSS 0.073