VendorsOracleutilities_framework4.3.0.6.0
Vulnerabilities

Oracle Utilities Framework 4.3.0.6.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2018-8088
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series.
Published 2018-03-20 · Modified
9.8EPSS 0.147
CVE-2019-17495
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of untrusted JSON data from remote servers, but it was not previously known that <style>@import within the JSON data was a functional attack method.
Published 2019-10-10 · Modified
9.8EPSS 0.057
CVE-2021-39139
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.8EPSS 0.045
CVE-2021-39144
XStream is vulnerable to a Remote Command Execution attack
Published 2021-08-23 · Analyzed
8.5KEVEPSS 0.981
CVE-2021-39141
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.161
CVE-2021-39146
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.143
CVE-2021-39152
A Server-Side Forgery Request vulnerability in XStream via HashMap unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.114
CVE-2021-39154
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39151
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39149
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39148
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39147
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.047
CVE-2021-39153
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.045
CVE-2021-39145
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.5EPSS 0.041
CVE-2021-39150
A Server-Side Forgery Request vulnerability in XStream via PriorityQueue unmarshaling
Published 2021-08-23 · Analyzed
8.5EPSS 0.034
CVE-2020-28052
An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
Published 2020-12-18 · Modified
8.1EPSS 0.072
CVE-2020-25649
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Published 2020-12-03 · Modified
7.5EPSS 0.173
CVE-2020-11979
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modified source files into the build process.
Published 2020-10-01 · Modified
7.5EPSS 0.080
CVE-2020-36518
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
Published 2022-03-11 · Modified
7.5EPSS 0.049
CVE-2021-39140
XStream can cause a Denial of Service
Published 2021-08-23 · Analyzed
6.5EPSS 0.059