Known Vulnerabilities for Endeca Information Discovery Studio by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Endeca Information Discovery Studio" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-21345 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerabil... | 9.9 - CRITICAL | 2021-03-23 | 2023-11-07 |
| CVE-2020-26217 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arb... | 8.8 - HIGH | 2020-11-16 | 2023-11-07 |
| CVE-2020-11979 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the curr... | 7.5 - HIGH | 2020-10-01 | 2023-11-07 |
| CVE-2020-1945 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property jav... | 6.3 - MEDIUM | 2020-05-14 | 2023-11-07 |
| CVE-2019-17571 | Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited ... | 9.8 - CRITICAL | 2019-12-20 | 2023-11-07 |
| CVE-2019-12415 | In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a speciall... | 5.5 - MEDIUM | 2019-10-23 | 2023-11-07 |
| CVE-2019-10173 | It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If th... | 9.8 - CRITICAL | 2019-07-23 | 2022-10-05 |
| CVE-2019-0227 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. ... | 7.5 - HIGH | 2019-05-01 | 2023-11-07 |
| CVE-2018-8032 | Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. | 6.1 - MEDIUM | 2018-08-02 | 2023-11-07 |
| CVE-2017-5645 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from... | 9.8 - CRITICAL | 2017-04-17 | 2023-11-07 |