VendorsOracleprimavera_unifier21.12
Vulnerabilities

Oracle Primavera Unifier 21.12

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2021-23450
Prototype Pollution
Published 2021-12-17 · Modified
9.8EPSS 0.304
CVE-2021-42575
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION elements.
Published 2021-10-18 · Modified
9.8EPSS 0.030
CVE-2021-44832
Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration
Published 2021-12-28 · Modified
8.5EPSS 0.979
CVE-2021-2351
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Published 2021-07-20 · Modified
8.3EPSS 0.024
CVE-2021-37714
Crafted input may cause the jsoup HTML and XML parser to get stuck, timeout, or throw unchecked exceptions
Published 2021-08-18 · Modified
7.5EPSS 0.069
CVE-2020-36518
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Published 2022-03-11 · Modified
7.5EPSS 0.049
CVE-2021-41184
XSS in the `of` option of the `.position()` util
Published 2021-10-26 · Modified
6.5EPSS 0.408
CVE-2021-41182
XSS in the `altField` option of the Datepicker widget
Published 2021-10-26 · Modified
6.5EPSS 0.394
CVE-2019-10219
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Published 2019-11-08 · Modified
6.5EPSS 0.022
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2021-3449
NULL pointer deref in signature_algorithms processing
Published 2021-03-25 · Modified
5.9EPSS 0.635
CVE-2021-38153
Timing Attack Vulnerability for Apache Kafka Connect and Clients
Published 2021-09-22 · Modified
5.9EPSS 0.063
CVE-2021-29425
Possible limited path traversal vulnerabily in Apache Commons IO
Published 2021-04-13 · Modified
5.8EPSS 0.102
CVE-2022-30126
Apache Tika Regular Expression Denial of Service in Standards Extractor
Published 2022-05-16 · Modified
5.5EPSS 0.026
CVE-2022-25169
Apache Tika BPGParser Memory Usage DoS
Published 2022-05-16 · Modified
5.5EPSS 0.022
CVE-2020-35460
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.
Published 2020-12-14 · Modified
5.3EPSS 0.019
CVE-2020-8908
Temp directory permission issue in Guava
Published 2020-12-10 · Modified
3.3EPSS 0.010