Filters

Oracle Retail Integration BusApache Log4j StrSubstitutor Uncontrolled Recursion Denial-of-Service Vulnerability

First published (updated )

redhat/rh-sso7-keycloakHTTP fails to validate against control chars in header names which may lead to HTTP request smuggling

First published (updated )

Oracle Primavera GatewayXSS in `*Text` options of the Datepicker widget

7.2
First published (updated )

Oracle Primavera UnifierXSS in the `of` option of the `.position()` util

7.2
First published (updated )

Oracle Primavera UnifierXSS in the `altField` option of the Datepicker widget

7.2
First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Banking Digital ExperienceVulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi…

8.3
First published (updated )

Oracle Banking Enterprise Default ManagementXSS

First published (updated )

Oracle Banking ApisApache Commons Compress 1.0 to 1.20 denial of service vulnerability

7.5
First published (updated )

Oracle Banking ApisPossible limited path traversal vulnerabily in Apache Commons IO

First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to a Remote Command Execution attack

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Communications Unified Inventory ManagementXStream can cause a Denial of Service

7.5
First published (updated )

Oracle Communications Unified Inventory ManagementA Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

8.6
First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights

7.5
First published (updated )

Oracle Communications Unified Inventory ManagementA Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host

First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an Arbitrary Code Execution attack

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)

7.8
First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an Arbitrary Code Execution attack

First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an Arbitrary Code Execution attack

First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an Arbitrary Code Execution attack

First published (updated )

Oracle Communications Unified Inventory ManagementXStream is vulnerable to an Arbitrary Code Execution attack

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Banking Enterprise Default ManagementVelocity Sandbox Bypass

First published (updated )

Oracle Banking PlatformFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

First published (updated )

Oracle Banking PlatformFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

8.1
First published (updated )

Oracle Banking PlatformFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg…

8.1
First published (updated )

Oracle Retail Xstore Point of ServiceRemote Code Execution in XStream

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Commerce MerchandisingXSS

First published (updated )

Oracle Banking PlatformCode Injection

7.5
First published (updated )

Oracle Retail Integration BusLast updated 24 July 2024

First published (updated )

Oracle REST Data ServicesPotential XSS vulnerability in jQuery

First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Oracle Banking Digital ExperienceFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Oracle Banking Digital ExperienceFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Oracle Banking Digital ExperienceFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Oracle Banking Digital ExperienceFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

redhat/eap7-elytron-webFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

redhat/eap7-elytron-webFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Oracle Banking Digital ExperienceFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

redhat/eap7-elytron-webFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

redhat/eap7-elytron-webFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

redhat/eap7-elytron-webFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadg…

First published (updated )

redhat/eap7-elytron-webPath Traversal

First published (updated )

Apache KafkaInfoleak

7.5
First published (updated )

Oracle Banking PlatformXEE

7.5
First published (updated )

Oracle Primavera UnifierFasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Oracle Banking PlatformXSS, XEE

First published (updated )

Oracle Banking PlatformOracle ADF Faces Deserialization of Untrusted Data Remote Code Execution Vulnerability

First published (updated )

Oracle Banking PlatformInput Validation

First published (updated )

Oracle Banking ApisCSRF, XSS

First published (updated )

Oracle Banking PlatformInfoleak

First published (updated )

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203