CVEs (59)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FasterxmlFedoraproject+3 more17Banking Platform Customer Management And Segmentation FoundationDebian Linux+14 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540. |
6Debian FasterxmlFedoraproject+3 more19Banking Platform Customer Management And Segmentation FoundationDebian Linux+16 moreJun 17, 2026 Sep 15, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariConfig. |
3Apache FedoraprojectOracle19Banking Payments Banking PlatformCommons Compress+16 moreJun 17, 2026 Aug 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker...Show more |
6Apache DebianFedoraproject+3 more60Agile Plm Agile Product Lifecycle Management Integration PackApplication Testing Suite+57 moreJun 17, 2026 Aug 20, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more |
6Apache DebianFasterxml+3 more18Banking Platform Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 moreJun 17, 2026 Jul 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more |
7Apple DebianFasterxml+4 more24Active Iq Unified Manager Banking PlatformCommunications Diameter Signaling Router+21 moreJun 17, 2026 Jul 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code ex...Show more |
2Apache Oracle37Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+34 moreJun 17, 2026 May 1, 2019 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legac...Show more |
11Backdropcms DebianDrupal+8 more105Agile Product Lifecycle Management For Process Application ExpressApplication Service Level Management+102 moreJun 17, 2026 Apr 20, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ p...Show more |
3Debian OracleVmware40Agile Plm Communications Brm Elastic Charging EngineCommunications Converged Application Server Service Controller+37 moreNov 21, 2024 Oct 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through t...Show more |
3Apache DebianOracle38Agile Engineering Data Management Agile Product Lifecycle ManagementApplication Testing Suite+35 moreJun 17, 2026 Aug 2, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. |
3Oracle RedhatVmware30Agile Product Lifecycle Management Application Testing SuiteBig Data Discovery+27 moreNov 21, 2024 May 11, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through t...Show more |
2Oracle Vmware19Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+16 moreNov 21, 2024 Apr 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
2Oracle Vmware25Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+22 moreNov 21, 2024 Apr 6, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (ser...Show more |
2Oracle Vmware28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static reso...Show more |
4Debian OracleRedhat+1 more28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
2Jquery Oracle47Agile Product Lifecycle Management For Process Banking PlatformBusiness Process Management Suite+44 moreNov 21, 2024 Jan 18, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. |
Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and 16.2. Easil...Show more |
Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration). Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and 16.2. Easil...Show more |
4Apache NetappOracle+1 more79Api Gateway Application Testing SuiteAutovue Vuelink Integration+76 moreMay 13, 2026 Apr 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, c...Show more |