Financial Services Crime And Compliance Management Studio
financial_services_crime_and_compliance_management_studio
Vendor: Oracle • 22 CVEs
CVEs (22)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityNov 21, 2024 May 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatc...Show more |
3Netapp OracleVmware3Active Iq Unified Manager Financial Services Crime And Compliance Management StudioSpring SecurityNov 21, 2024 May 19, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder...Show more |
3Netapp OracleVmware4Cloud Secure Agent Financial Services Crime And Compliance Management StudioOncommand Insight+1 moreNov 21, 2024 May 12, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. |
3Netapp OracleVmware6Active Iq Unified Manager Brocade San NavigatorCloud Secure Agent+3 moreNov 21, 2024 May 12, 2022 N/A· v4 5.3 MEDIUM· v3 3.5 LOW· v2 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servle...Show more |
3Netapp NettyOracle5Active Iq Unified Manager Financial Services Crime And Compliance Management StudioNetty+2 moreNov 21, 2024 May 6, 2022 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 Netty is an open-source, asynchronous event-driven network application framework. The package `io.netty:netty-codec-http` prior to version 4.1.77.Final contains an insufficient fix for CVE-2021-21290. When Netty's multip...Show more |
4Debian GoogleNetapp+1 more6Active Iq Unified Manager Debian LinuxFinancial Services Crime And Compliance Management Studio+3 moreNov 21, 2024 May 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package com.google.code.gson:gson before 2.8.9 are vulnerable to Deserialization of Untrusted Data via the writeReplace() method in internal classes, which may lead to DoS attacks. |
4Debian FasterxmlNetapp+1 more36Active Iq Unified Manager Big Data Spatial And GraphCloud Insights Acquisition Unit+33 moreAug 27, 2025 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
2Apache Oracle2Financial Services Crime And Compliance Management Studio SparkNov 21, 2024 Mar 10, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Spark supports end-to-end encryption of RPC connections via "spark.authenticate" and "spark.network.crypto.enabled". In versions 3.1.2 and earlier, it uses a bespoke mutual authentication protocol that allows for...Show more |
3Apache DebianOracle7Agile Engineering Data Management Communications Cloud Native Core PolicyDebian Linux+4 moreNov 21, 2024 Jan 27, 2022 N/A· v4 7.0 HIGH· v3 3.7 LOW· v2 The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to...Show more |
3Apache NetappOracle29Active Iq Unified Manager Agile Engineering Data ManagementAgile Plm+26 moreNov 21, 2024 Jan 24, 2022 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consu...Show more |
2Apache Oracle2Financial Services Crime And Compliance Management Studio ShiroNov 21, 2024 Sep 17, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Shiro before 1.8.0, when using Apache Shiro with Spring Boot, a specially crafted HTTP request may cause an authentication bypass. Users should update to Apache Shiro 1.8.0. |
4Jsoup NetappOracle+1 more16Banking Trade Finance Banking Treasury ManagementBusiness Process Management Suite+13 moreNov 21, 2024 Aug 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on user supplied input, an attacker may supp...Show more |
3Eclipse NetappOracle18Autovue For Agile Product Lifecycle Management Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Security Edge Protection Proxy+15 moreNov 21, 2024 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a...Show more |
3Apache NetappOracle34Active Iq Unified Manager Banking ApisBanking Digital Experience+31 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle27Active Iq Unified Manager Banking ApisBanking Digital Experience+24 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle24Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+21 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of servi...Show more |
3Apache NetappOracle26Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+23 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that us...Show more |
4Lodash NetappOracle+1 more23Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+20 moreNov 21, 2024 Feb 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
3Lodash OracleSiemens19Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Extensibility Workbench+16 moreNov 21, 2024 Feb 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions. |
2Apache Oracle3Financial Services Crime And Compliance Management Studio HadoopSolrNov 21, 2024 Jan 26, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Apache Hadoop 3.2.0 to 3.2.1, 3.0.0-alpha1 to 3.1.3, and 2.0.0-alpha to 2.10.0, WebHDFS client might send SPNEGO authorization header to remote URL without proper verification. |