CVEs (39)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Dell Oracle18Application Performance Management Bsafe Cert JBsafe Crypto J+15 moreJun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulne...Show more |
2Dell Oracle16Application Performance Management Bsafe Cert JBsafe Crypto J+13 moreJun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulner...Show more |
3Dell McafeeOracle16Application Performance Management Bsafe Cert JBsafe Crypto J+13 moreJun 17, 2026 Sep 18, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into comput...Show more |
3Apache FedoraprojectOracle19Banking Payments Banking PlatformCommons Compress+16 moreJun 17, 2026 Aug 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker...Show more |
5Apache AtlassianNetapp+2 more31Active Iq Unified Manager Apache Batik MapviewerBanking Enterprise Originations+28 moreJun 17, 2026 Jul 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. |
3Debian OracleVmware40Agile Plm Communications Brm Elastic Charging EngineCommunications Converged Application Server Service Controller+37 moreNov 21, 2024 Oct 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through t...Show more |
5Debian Dom4j ProjectNetapp+2 more14Debian Linux Dom4jFlexcube Investor Servicing+11 moreNov 21, 2024 Aug 20, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection....Show more |
3Debian OracleVmware33Agile Plm Application Testing SuiteCommunications Diameter Signaling Router+30 moreNov 21, 2024 Jun 25, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the Hid...Show more |
4Apache CanonicalDebian+1 more21Batik Business IntelligenceCommunications Diameter Signaling Router+18 moreJun 17, 2026 May 24, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name which then use it to call the no-arg constructor of the class. Fix was t...Show more |
5Netapp OraclePivotal Software+2 more42Agile Plm Application Testing SuiteBig Data Discovery+39 moreNov 21, 2024 May 11, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to met...Show more |
3Google OracleRedhat17Banking Payments Communications Ip Service ActivatorCustomer Management And Segmentation Foundation+14 moreNov 21, 2024 Apr 26, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data,...Show more |
1Oracle 1Retail Integration Bus Nov 21, 2024 Apr 19, 2018 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 Vulnerability in the Oracle Retail Integration Bus component of Oracle Retail Applications (subcomponent: RIB Kernal(Apache Commons Collections)). The supported version that is affected is 13.2. Easily exploitable vulner...Show more |
2Oracle Vmware25Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+22 moreNov 21, 2024 Apr 6, 2018 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (ser...Show more |
2Oracle Vmware28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static reso...Show more |
4Debian OracleRedhat+1 more28Application Testing Suite Big Data DiscoveryCommunications Converged Application Server+25 moreNov 21, 2024 Apr 6, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the...Show more |
4Apache NetappOracle+1 more79Api Gateway Application Testing SuiteAutovue Vuelink Integration+76 moreMay 13, 2026 Apr 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, c...Show more |
Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows remote authenticated users to affect confidentiality, integrity, and av...Show more |
1Oracle 1Retail Integration Bus May 6, 2026 Jul 21, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unspecified vulnerability in the Oracle Retail Integration Bus component in Oracle Retail Applications 13.0, 13.1, 13.2, 14.0, 14.1, and 15.0 allows remote attackers to affect confidentiality, integrity, and availability...Show more |
1Oracle 11Documaker Enterprise Manager Ops CenterHealth Sciences Information Manager+8 moreMay 6, 2026 Jul 21, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sci...Show more |