VendorsOracleretail_price_management14.0.3
Vulnerabilities

Oracle Retail Price Management 14.0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2020-10683
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any application that uses dom4j.
Published 2020-05-01 · Modified
9.8EPSS 0.073