Known Vulnerabilities for Banking Supply Chain Finance by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Banking Supply Chain Finance" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-22963 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possibl... | 9.8 - CRITICAL | 2022-04-01 | 2023-07-13 |
| CVE-2021-31812 | In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache... | 5.5 - MEDIUM | 2021-06-12 | 2023-11-07 |
| CVE-2021-31811 | In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affect... | 5.5 - MEDIUM | 2021-06-12 | 2023-11-07 |
| CVE-2021-29505 | XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 m... | 8.8 - HIGH | 2021-05-28 | 2023-11-07 |
| CVE-2021-27906 | A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox ve... | 5.5 - MEDIUM | 2021-03-19 | 2023-11-07 |
| CVE-2021-23337 | Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. | 7.2 - HIGH | 2021-02-15 | 2022-09-13 |
| CVE-2020-24750 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related t... | 8.1 - HIGH | 2020-09-17 | 2023-09-13 |
| CVE-2020-24616 | FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related t... | 8.1 - HIGH | 2020-08-25 | 2023-11-07 |
| CVE-2020-8203 | Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20. | 7.4 - HIGH | 2020-07-15 | 2024-01-21 |
| CVE-2020-5413 | Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is c... | 9.8 - CRITICAL | 2020-07-31 | 2022-05-12 |