CVE-2020-10683
- EPSS 6.96%
- Veröffentlicht 01.05.2020 19:15:12
- Zuletzt bearbeitet 21.11.2024 04:55:50
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default behavior in any a...
CVE-2019-10219
- EPSS 1.67%
- Veröffentlicht 08.11.2019 15:15:11
- Zuletzt bearbeitet 07.07.2025 14:15:21
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
CVE-2019-10086
- EPSS 1.24%
- Veröffentlicht 20.08.2019 21:15:12
- Zuletzt bearbeitet 21.11.2024 04:18:22
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by defa...
CVE-2018-3108
- EPSS 0.56%
- Veröffentlicht 02.08.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:11
Vulnerability in the Oracle Fusion Middleware component of Oracle Fusion Middleware (subcomponent: Oracle Notification Service). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Difficult to exploit vulnerability allows low privileged ...
CVE-2018-3109
- EPSS 0.75%
- Veröffentlicht 02.08.2018 12:29:00
- Zuletzt bearbeitet 21.11.2024 04:05:11
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder). Supported versions that are affected are 12.2.1.2 and 12.2.1.3. Easily exploitable vulnerability allows low privileged attacker...
CVE-2018-1304
- EPSS 3.04%
- Veröffentlicht 28.02.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definiti...
CVE-2018-1305
- EPSS 21.58%
- Veröffentlicht 23.02.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:35
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way ap...
CVE-2016-0470
- EPSS 0.16%
- Veröffentlicht 21.01.2016 03:00:17
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in the Oracle BI Publisher component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, and 12.2.1.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to BI Publisher Se...
CVE-2016-0464
- EPSS 0.46%
- Veröffentlicht 21.01.2016 03:00:13
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via vectors related to WLS-Console.
CVE-2016-0453
- EPSS 0.52%
- Veröffentlicht 21.01.2016 03:00:02
- Zuletzt bearbeitet 06.05.2026 22:30:45
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.1.2 allows remote attackers to affect integrity via unknown vectors related to Embedded Server.