Vulnerabilities > Oracle > JD Edwards Enterpriseone Tools > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-07-18 CVE-2018-2948 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime).
network
low complexity
oracle
6.1
2018-07-18 CVE-2018-2947 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime).
network
low complexity
oracle
6.5
2018-07-18 CVE-2018-2946 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime).
network
low complexity
oracle
6.1
2018-07-18 CVE-2018-2945 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime).
network
low complexity
oracle
6.1
2018-01-18 CVE-2015-9251 Cross-site Scripting vulnerability in multiple products
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
network
low complexity
jquery oracle CWE-79
6.1
2018-01-18 CVE-2018-2659 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC).
network
low complexity
oracle
6.1
2018-01-18 CVE-2018-2658 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC).
network
low complexity
oracle
6.1
2017-12-01 CVE-2017-15707 Improper Input Validation vulnerability in multiple products
In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a DoS attack using malicious request with specially crafted JSON payload.
local
low complexity
apache netapp oracle CWE-20
6.2
2017-04-24 CVE-2017-3517 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools 9.2
Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC).
network
low complexity
oracle
6.5
2015-07-09 CVE-2015-1793 7PK - Security Features vulnerability in multiple products
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly process X.509 Basic Constraints cA values during identification of alternative certificate chains, which allows remote attackers to spoof a Certification Authority role and trigger unintended certificate verifications via a valid leaf certificate.
network
low complexity
oracle openssl CWE-254
6.5