Vulnerabilities > Oracle

DATE CVE VULNERABILITY TITLE RISK
2020-01-16 CVE-2019-17573 Cross-site Scripting vulnerability in multiple products
By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses.
network
low complexity
apache oracle CWE-79
6.1
2020-01-16 CVE-2019-12423 Insufficiently Protected Credentials vulnerability in multiple products
Apache CXF ships with a OpenId Connect JWK Keys service, which allows a client to obtain the public keys in JWK format, which can then be used to verify the signature of tokens issued by the service.
network
low complexity
apache oracle CWE-522
7.5
2020-01-16 CVE-2020-7044 Off-by-one Error vulnerability in multiple products
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash.
network
low complexity
wireshark fedoraproject opensuse oracle CWE-193
7.5
2020-01-15 CVE-2020-2731 Unspecified vulnerability in Oracle Database Server
Vulnerability in the Core RDBMS component of Oracle Database Server.
local
low complexity
oracle
3.9
2020-01-15 CVE-2020-2730 Unrestricted Upload of File with Dangerous Type vulnerability in Oracle Revenue Management and Billing 2.7.0.0/2.7.0.1/2.8.0.0
Vulnerability in the Oracle Financial Services Revenue Management and Billing product of Oracle Financial Services Applications (component: File Upload).
network
low complexity
oracle CWE-434
5.4
2020-01-15 CVE-2020-2729 Unspecified vulnerability in Oracle Identity Manager 11.1.2.3.0/12.2.1.3.0
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Advanced Console).
network
low complexity
oracle
5.4
2020-01-15 CVE-2020-2728 Unspecified vulnerability in Oracle Identity Manager 12.2.1.3.0
Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM - LDAP user and role Synch).
network
low complexity
oracle
7.5
2020-01-15 CVE-2020-2727 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
low complexity
oracle
6.0
2020-01-15 CVE-2020-2726 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
high complexity
oracle
7.5
2020-01-15 CVE-2020-2725 Unspecified vulnerability in Oracle VM Virtualbox
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).
local
low complexity
oracle
6.5