VendorsOraclemysql_enterprise_monitorall versions
Vulnerabilities

Oracle MySQL Enterprise Monitor

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

58CVEs
CVE-2020-9484
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.
Published 2020-05-20 · Modified
7.0EPSS 0.555
CVE-2021-25329
Incomplete fix for CVE-2020-9484
Published 2021-03-01 · Modified
7.0EPSS 0.095
CVE-2022-23181
Local privilege escalation with FileStore
Published 2022-01-27 · Modified
7.0EPSS 0.007
CVE-2021-41182
XSS in the `altField` option of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.394
CVE-2021-41183
XSS in `*Text` options of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.085
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2019-1559
0-byte record padding oracle
Published 2019-02-27 · Modified
5.9EPSS 0.171
CVE-2021-23841
Null pointer deref in X509_issuer_and_serial_hash()
Published 2021-02-16 · Modified
5.9EPSS 0.074
CVE-2018-11039
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Published 2018-06-25 · Modified
5.9EPSS 0.027
CVE-2020-1935
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Published 2020-02-24 · Modified
5.8EPSS 0.094
CVE-2019-17569
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Published 2020-02-24 · Modified
5.8EPSS 0.089
CVE-2021-33037
Incorrect Transfer-Encoding handling with HTTP/1.0
Published 2021-07-12 · Modified
5.3EPSS 0.747
CVE-2019-1551
rsaz_512_sqr overflow bug on x86_64
Published 2019-12-06 · Modified
5.3EPSS 0.143
CVE-2021-44532
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a certificate chain, allowing the bypass of these name constraints.Versions of Node.js with the fix for this escape SANs containing the problematic characters in order to prevent the injection. This behavior can be reverted through the --security-revert command-line option.
Published 2022-02-24 · Modified
5.3EPSS 0.104
CVE-2021-44533
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to inject a Common Name that would allow bypassing the certificate subject verification.Affected versions of Node.js that do not accept multi-value Relative Distinguished Names and are thus not vulnerable to such attacks themselves. However, third-party code that uses node's ambiguous presentation of certificate subjects may be vulnerable.
Published 2022-02-24 · Modified
5.3EPSS 0.094
CVE-2022-22968
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
Published 2022-04-14 · Modified
5.3EPSS 0.057
CVE-2020-5397
CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux
Published 2020-01-17 · Modified
5.3EPSS 0.024
CVE-2017-3307
Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Server). Supported versions that are affected are 3.1.6.8003 and earlier, 3.2.1182 and earlier and 3.3.2.1162 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Enterprise Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Enterprise Monitor. CVSS 3.0 Base Score 3.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L).
Published 2017-04-24 · Modified
3.6EPSS 0.011
← Prev2 / 2