Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-35043 OWASP AntiSamy before 1.6.4 allows XSS via HTML attributes when using the HTML output serializer (XHTML is not affected). Thi... 6.1 - MEDIUM 2021-07-19 2022-10-29
CVE-2021-2351 Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are... 8.3 - HIGH 2021-07-21 2022-10-06
CVE-2020-11987 Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. B... 8.2 - HIGH 2021-02-24 2022-07-25
CVE-2020-11022 In jQuery versions greater than or equal to 1.2 and before 3.5.0, passing HTML from untrusted sources - even after sanitizing... 6.1 - MEDIUM 2020-04-29 2022-07-25
CVE-2020-5421 In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, t... 6.5 - MEDIUM 2020-09-19 2022-06-23
CVE-2020-5398 In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an ap... 7.5 - HIGH 2020-01-17 2022-07-25
CVE-2020-5397 Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Sp... 5.3 - MEDIUM 2020-01-17 2022-07-25
CVE-2020-1945 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property jav... 6.3 - MEDIUM 2020-05-14 2022-04-04
CVE-2019-10219 A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consi... 6.1 - MEDIUM 2019-11-08 2022-09-12
CVE-2019-10086 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an att... 7.3 - HIGH 2019-08-20 2022-07-25

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationOracleRetail Returns Management2.4.9AllAllAll
ApplicationOracleRetail Returns Management2.3.8AllAllAll
ApplicationOracleRetail Returns Management14.1.3AllAllAll
ApplicationOracleRetail Returns Management14.1AllAllAll
ApplicationOracleRetail Returns Management14.0.4AllAllAll
ApplicationOracleRetail Returns Management14.0AllAllAll

