Vulnerabilities > Oracle > Peoplesoft Enterprise Peopletools > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-03-15 CVE-2021-28363 Improper Certificate Validation vulnerability in multiple products
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies.
network
low complexity
python fedoraproject oracle CWE-295
6.5
2021-02-23 CVE-2021-27568 Improper Check for Unusual or Exceptional Conditions vulnerability in multiple products
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4.
network
high complexity
json-smart-project oracle CWE-754
5.9
2021-02-16 CVE-2021-23841 NULL Pointer Dereference vulnerability in multiple products
The OpenSSL public API function X509_issuer_and_serial_hash() attempts to create a unique hash value based on the issuer and serial number data contained within an X509 certificate.
5.9
2021-02-15 CVE-2021-23337 Code Injection vulnerability in multiple products
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
network
low complexity
lodash oracle netapp siemens CWE-94
6.5
2021-02-15 CVE-2020-28500 Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
network
low complexity
lodash oracle siemens
5.0
2021-01-20 CVE-2021-2071 Unspecified vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.56/8.57/8.58
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search).
network
oracle
6.8
2021-01-20 CVE-2021-2063 Unspecified vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.56/8.57/8.58
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal).
local
low complexity
oracle
4.6
2021-01-20 CVE-2021-2043 Unspecified vulnerability in Oracle Peoplesoft Enterprise Peopletools 8.56/8.57/8.58
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal).
network
oracle
5.8
2020-12-08 CVE-2020-1971 NULL Pointer Dereference vulnerability in multiple products
The X.509 GeneralName type is a generic type for representing different types of names.
5.9
2020-12-02 CVE-2020-13956 Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed to the library as java.net.URI object and pick the wrong target host for request execution.
network
low complexity
apache quarkus oracle netapp
5.3