Oracle

Managed File Transfer

22 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 75.35%
  • Veröffentlicht 12.07.2021 15:15:08
  • Zuletzt bearbeitet 25.08.2026 16:28:27

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specific...

  • EPSS 9.49%
  • Veröffentlicht 01.03.2021 12:15:14
  • Zuletzt bearbeitet 25.08.2026 16:28:27

The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnera...

  • EPSS 18.11%
  • Veröffentlicht 01.03.2021 12:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and use...

  • EPSS 86.61%
  • Veröffentlicht 14.07.2020 15:15:11
  • Zuletzt bearbeitet 25.08.2026 16:28:27

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with inv...

  • EPSS 64.12%
  • Veröffentlicht 14.07.2020 15:15:11
  • Zuletzt bearbeitet 25.08.2026 16:28:27

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException co...

  • EPSS 56.64%
  • Veröffentlicht 20.05.2020 19:15:09
  • Zuletzt bearbeitet 25.08.2026 16:28:27

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the Persiste...

  • EPSS 2.17%
  • Veröffentlicht 08.11.2019 15:15:11
  • Zuletzt bearbeitet 25.08.2026 16:28:27

A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.

  • EPSS 8.95%
  • Veröffentlicht 08.10.2019 14:15:10
  • Zuletzt bearbeitet 12.05.2025 17:37:16

The ASN.1 parser in Bouncy Castle Crypto (aka BC Java) 1.63 can trigger a large attempted memory allocation, and resultant OutOfMemoryError error, via crafted ASN.1 data. This is fixed in 1.64.

  • EPSS 1.14%
  • Veröffentlicht 16.01.2019 19:30:35
  • Zuletzt bearbeitet 21.11.2024 04:41:04

Vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware (subcomponent: MFT Runtime Server). Supported versions that are affected are 19.1.0.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged att...

  • EPSS 4.77%
  • Veröffentlicht 09.07.2018 20:29:00
  • Zuletzt bearbeitet 12.05.2025 17:37:16

Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in XMSS/XMSS^MT priv...