CVE-2020-10673
- EPSS 8.03%
- Veröffentlicht 18.03.2020 22:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2020-9281
- EPSS 4.33%
- Veröffentlicht 07.03.2020 01:15:15
- Zuletzt bearbeitet 25.08.2026 16:28:27
A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).
CVE-2020-9548
- EPSS 18.35%
- Veröffentlicht 02.03.2020 04:15:11
- Zuletzt bearbeitet 08.10.2026 19:16:55
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
CVE-2020-9546
- EPSS 4.61%
- Veröffentlicht 02.03.2020 04:15:10
- Zuletzt bearbeitet 07.10.2026 21:17:02
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
CVE-2020-1938
- EPSS 99.27%
- Veröffentlicht 24.02.2020 22:15:12
- Zuletzt bearbeitet 25.08.2026 16:28:27
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available t...
CVE-2019-17569
- EPSS 8.87%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 25.08.2026 16:28:27
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of H...
CVE-2020-1935
- EPSS 9.39%
- Veröffentlicht 24.02.2020 22:15:11
- Zuletzt bearbeitet 08.10.2026 21:17:24
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smug...
CVE-2019-10219
- EPSS 2.17%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 08.10.2026 22:16:49
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-10086
- EPSS 29.95%
- Veröffentlicht 20.08.2019 21:15:12
- Zuletzt bearbeitet 08.10.2026 22:16:48
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2019-2817
- EPSS 1.03%
- Veröffentlicht 23.07.2019 23:15:43
- Zuletzt bearbeitet 21.11.2024 04:41:37
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Folders, Files & Attachments). Supported versions that are affected are 9.3.3, 9.3.4, 9.3.5 and 9.3.6. Difficult to exploit vulnerability allows low ...