Oracle

Retail Xstore Point Of Service

127 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 21.07.2026 21:32:03
  • Zuletzt bearbeitet 07.08.2026 20:32:37

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with netw...

  • EPSS 0.11%
  • Veröffentlicht 21.07.2026 21:31:26
  • Zuletzt bearbeitet 07.08.2026 20:19:51

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobile). The supported version that is affected is 21.0.3. Easily exploitable vulnerability allows low privileged attacker with logo...

Warnung Exploit
  • EPSS 99.94%
  • Veröffentlicht 01.04.2022 23:15:13
  • Zuletzt bearbeitet 30.10.2025 19:56:53

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access ...

Warnung Exploit
  • EPSS 99.68%
  • Veröffentlicht 01.04.2022 23:15:13
  • Zuletzt bearbeitet 30.10.2025 19:56:43

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Sp...

Exploit
  • EPSS 7.93%
  • Veröffentlicht 01.02.2022 12:15:08
  • Zuletzt bearbeitet 03.11.2025 22:15:52

XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resul...

Warnung
  • EPSS 97.91%
  • Veröffentlicht 28.12.2021 20:15:08
  • Zuletzt bearbeitet 29.05.2026 20:16:21

Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has ...

Exploit
  • EPSS 11.38%
  • Veröffentlicht 23.08.2021 19:15:13
  • Zuletzt bearbeitet 23.05.2025 16:47:47

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed inp...

Exploit
  • EPSS 3.44%
  • Veröffentlicht 23.08.2021 19:15:12
  • Zuletzt bearbeitet 23.05.2025 16:48:02

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by manipulating the processed inp...

Exploit
  • EPSS 5.92%
  • Veröffentlicht 23.08.2021 19:15:10
  • Zuletzt bearbeitet 23.05.2025 16:50:34

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload r...

Exploit
  • EPSS 4.74%
  • Veröffentlicht 23.08.2021 18:15:13
  • Zuletzt bearbeitet 23.05.2025 16:47:35

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user...