VendorsOracleinsurance_rules_palette10.2.4
Vulnerabilities

Oracle Insurance Rules Palette 10.2.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2020-10683
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Published 2020-05-01 · Modified
9.8EPSS 0.073
CVE-2020-5421
RFD Protection Bypass via jsessionid
Published 2020-09-19 · Modified
8.7EPSS 0.107
CVE-2020-5398
RFD Attack via "Content-Disposition" Header Sourced from Request Input by Spring MVC or Spring WebFlux Application
Published 2020-01-16 · Modified
8.0EPSS 0.888
CVE-2018-15756
DoS Attack via Range Requests
Published 2018-10-18 · Modified
7.5EPSS 0.092
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Published 2019-11-08 · Modified
6.5EPSS 0.022
CVE-2019-12415
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External Entity (XXE) Processing.
Published 2019-10-23 · Modified
5.5EPSS 0.010
CVE-2020-5397
CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux
Published 2020-01-17 · Modified
5.3EPSS 0.024