CVE-2024-21284
- EPSS 0.26%
- Veröffentlicht 15.10.2024 20:15:21
- Zuletzt bearbeitet 18.10.2024 16:45:58
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacke...
CVE-2024-21285
- EPSS 0.26%
- Veröffentlicht 15.10.2024 20:15:21
- Zuletzt bearbeitet 18.10.2024 16:46:27
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Reports). The supported version that is affected is 14.5.0.12.0. Difficult to exploit vulnerability allows low privileged attacke...
CVE-2024-21281
- EPSS 0.11%
- Veröffentlicht 15.10.2024 20:15:20
- Zuletzt bearbeitet 10.02.2025 23:15:12
Vulnerability in the Oracle Banking Liquidity Management product of Oracle Financial Services Applications (component: Infrastructure). The supported version that is affected is 14.7.0.6.0. Difficult to exploit vulnerability allows high privileged ...
CVE-2022-22963
- EPSS 94.46%
- Veröffentlicht 01.04.2022 23:15:13
- Zuletzt bearbeitet 13.03.2025 16:36:53
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access ...
CVE-2020-24750
- EPSS 2.11%
- Veröffentlicht 17.09.2020 19:15:13
- Zuletzt bearbeitet 21.11.2024 05:16:00
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
CVE-2020-24616
- EPSS 3.78%
- Veröffentlicht 25.08.2020 18:15:11
- Zuletzt bearbeitet 21.11.2024 05:15:09
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
CVE-2020-8203
- EPSS 2.44%
- Veröffentlicht 15.07.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:38:29
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
CVE-2020-1945
- EPSS 0.02%
- Veröffentlicht 14.05.2020 16:15:12
- Zuletzt bearbeitet 21.11.2024 05:11:42
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files fr...
CVE-2019-12399
- EPSS 3.16%
- Veröffentlicht 14.01.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 04:22:45
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring...