CVE-2019-0227
- EPSS 91.94%
- Veröffentlicht 01.05.2019 21:29:00
- Zuletzt bearbeitet 08.05.2025 18:13:51
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to buil...
CVE-2019-2725
- EPSS 99.96%
- Veröffentlicht 26.04.2019 19:29:00
- Zuletzt bearbeitet 01.10.2026 21:17:15
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with ...
CVE-2018-15756
- EPSS 9.51%
- Veröffentlicht 18.10.2018 22:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:45
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler,...
CVE-2018-8032
- EPSS 10.55%
- Veröffentlicht 02.08.2018 13:29:00
- Zuletzt bearbeitet 08.05.2025 18:13:51
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
CVE-2018-11039
- EPSS 2.78%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:44
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring ...
CVE-2018-11040
- EPSS 3.24%
- Veröffentlicht 25.06.2018 15:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:44
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controlle...
CVE-2018-1257
- EPSS 3.24%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 08.10.2026 22:16:46
Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A ...
CVE-2018-1258
- EPSS 2.46%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 25.08.2026 16:28:27
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted...
CVE-2018-2609
- EPSS 0.84%
- Veröffentlicht 18.01.2018 02:29:19
- Zuletzt bearbeitet 08.05.2025 18:13:51
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network ac...
CVE-2017-10299
- EPSS 1%
- Veröffentlicht 19.10.2017 17:29:02
- Zuletzt bearbeitet 13.05.2026 00:24:29
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite (subcomponent: Security). Supported versions that are affected are 9.3.5 and 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network acc...