VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Oracle
>
Primavera P6 Enterprise Project Portfolio Management
> 18.8.19.0
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2022-03-11
CVE-2020-36518
Out-of-bounds Write vulnerability in multiple products
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
network
low complexity
fasterxml
oracle
debian
netapp
CWE-787
7.5
7.5
2020-09-19
CVE-2020-5421
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
network
high complexity
vmware
oracle
netapp
6.5
6.5
2020-07-15
CVE-2020-14706
Unspecified vulnerability in Oracle Primavera P6 Enterprise Project Portfolio Management
Vulnerability in the Primavera P6 Enterprise Project Portfolio Management product of Oracle Construction and Engineering (component: Web Access).
network
high complexity
oracle
5.9
5.9
2020-05-01
CVE-2020-10683
XXE vulnerability in multiple products
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks.
network
low complexity
dom4j-project
oracle
opensuse
netapp
canonical
CWE-611
critical
9.8
9.8
2019-11-08
CVE-2019-10219
A vulnerability was found in Hibernate-Validator.
network
low complexity
redhat
netapp
oracle
6.1
6.1
2018-08-20
CVE-2018-1000632
XML Injection (aka Blind XPath Injection) vulnerability in multiple products
dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element.
network
low complexity
dom4j-project
debian
oracle
redhat
netapp
CWE-91
7.5
7.5