Known Vulnerabilities for Banking Digital Experience by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Banking Digital Experience" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-37137 | The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it ... | 7.5 - HIGH | 2021-10-19 | 2023-11-07 |
| CVE-2021-37136 | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affec... | 7.5 - HIGH | 2021-10-19 | 2023-11-07 |
| CVE-2021-36090 | When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to ... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35517 | When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to ... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35516 | When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to a... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-35515 | When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an... | 7.5 - HIGH | 2021-07-13 | 2023-11-07 |
| CVE-2021-29425 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../f... | 4.8 - MEDIUM | 2021-04-13 | 2023-11-07 |
| CVE-2021-28164 | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e... | 5.3 - MEDIUM | 2021-04-01 | 2023-11-07 |
| CVE-2021-28163 | In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory tha... | 2.7 - LOW | 2021-04-01 | 2023-11-07 |
| CVE-2021-2351 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are... | 8.3 - HIGH | 2021-07-21 | 2023-10-23 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Banking Digital Experience | 20.1 | All | All | All |
| Application | Oracle | Banking Digital Experience | 19.2 | All | All | All |
| Application | Oracle | Banking Digital Experience | 19.1 | All | All | All |
| Application | Oracle | Banking Digital Experience | 18.3 | All | All | All |
| Application | Oracle | Banking Digital Experience | 18.2 | All | All | All |
| Application | Oracle | Banking Digital Experience | 18.1 | All | All | All |