Known Vulnerabilities for Fineract by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Fineract" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-25197 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundat... | 6.3 - MEDIUM | 2023-03-28 | 2023-11-07 |
| CVE-2023-25196 json | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundat... | 4.3 - MEDIUM | 2023-03-28 | 2023-11-07 |
| CVE-2023-25195 json | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited... | 8.1 - HIGH | 2023-03-28 | 2023-11-07 |
| CVE-2022-44635 json | Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a fil... | 8.8 - HIGH | 2022-11-29 | 2022-12-01 |
| CVE-2020-17514 json | Apache Fineract prior to 1.5.0 disables HTTPS hostname verification in ProcessorHelper in the configureClient method. Under t... | 7.4 - HIGH | 2021-05-27 | 2023-11-07 |
| CVE-2018-20243 json | The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is ... | 7.5 - HIGH | 2020-10-13 | 2020-10-16 |
| CVE-2018-11801 json | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on... | 9.8 - CRITICAL | 2019-06-11 | 2023-11-07 |
| CVE-2018-11800 json | SQL injection vulnerability in Apache Fineract before 1.3.0 allows attackers to execute arbitrary SQL commands via a query on... | 9.8 - CRITICAL | 2019-06-11 | 2023-11-07 |
| CVE-2018-1292 json | Within the 'getReportType' method in Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating, a hacker co... | 8.1 - HIGH | 2018-04-20 | 2023-11-07 |
| CVE-2018-1291 json | Apache Fineract 1.0.0, 0.6.0-incubating, 0.5.0-incubating, 0.4.0-incubating exposes different REST end points to query domain... | 8.1 - HIGH | 2018-04-20 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Fineract | 1.4.0 | |||
| Application | Apache | Fineract | 1.3.0 | |||
| Application | Apache | Fineract | 1.2.0 | |||
| Application | Apache | Fineract | 1.1.0 | |||
| Application | Apache | Fineract | 1.0.0 | |||
| Application | Apache | Fineract | 0.6.0-incubating | |||
| Application | Apache | Fineract | 0.6.0 | |||
| Application | Apache | Fineract | 0.6.0 | |||
| Application | Apache | Fineract | 0.5.0-incubating | |||
| Application | Apache | Fineract | 0.5.0 | |||
| Application | Apache | Fineract | 0.5.0 | |||
| Application | Apache | Fineract | 0.4.0-incubating | |||
| Application | Apache | Fineract | 0.4.0 | |||
| Application | Apache | Fineract | 0.4.0 | |||
| Application | Apache | Fineract | 0.3.2 | |||
| Application | Apache | Fineract | 0.3.1 | |||
| Application | Apache | Fineract | 0.1.2 |