VendorsOraclehospitality_cruise_shipboard_property_management_system20.1.0
Vulnerabilities

Oracle Hospitality Cruise Shipboard Property Management System 20.1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2021-22112
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application.
Published 2021-02-23 · Modified
9.0EPSS 0.032
CVE-2021-42340
DoS via memory leak with WebSocket connections
Published 2021-10-14 · Modified
7.5EPSS 0.118
CVE-2021-30640
Auth weakness in JNDIRealm
Published 2021-07-12 · Modified
6.5EPSS 0.099
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Published 2019-11-08 · Modified
6.5EPSS 0.022
CVE-2021-33037
Incorrect Transfer-Encoding handling with HTTP/1.0
Published 2021-07-12 · Modified
5.3EPSS 0.747