Known Vulnerabilities for Flexcube Core Banking by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Flexcube Core Banking" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-29425 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../f... | 4.8 - MEDIUM | 2021-04-13 | 2023-11-07 |
| CVE-2020-27216 | In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, o... | 7 - HIGH | 2020-10-23 | 2023-11-07 |
| CVE-2020-10683 | dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attac... | 9.8 - CRITICAL | 2020-05-01 | 2023-11-07 |
| CVE-2020-9488 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to ... | 3.7 - LOW | 2020-04-27 | 2023-11-07 |
| CVE-2020-2955 | Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Transaction P... | 6.3 - MEDIUM | 2020-04-15 | 2020-04-16 |
| CVE-2019-10247 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and... | 5.3 - MEDIUM | 2019-04-22 | 2023-11-07 |
| CVE-2019-10246 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qua... | 5.3 - MEDIUM | 2019-04-22 | 2023-11-07 |
| CVE-2019-10241 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions... | 6.1 - MEDIUM | 2019-04-22 | 2023-11-07 |
| CVE-2019-0227 | A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. ... | 7.5 - HIGH | 2019-05-01 | 2023-11-07 |
| CVE-2018-2807 | Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Securiti... | 6.1 - MEDIUM | 2018-04-19 | 2019-10-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Flexcube Core Banking | 5.2.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | 5.1.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | 4.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | 11.7.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | 11.6.0 | All | All | All |
| Application | Oracle | Flexcube Core Banking | 11.5.0 | All | All | All |