Vulnerabilities > Oracle > Retail Customer Management AND Segmentation Foundation > 18.0

DATE CVE VULNERABILITY TITLE RISK
2020-09-19 CVE-2020-5421 In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
network
high complexity
vmware oracle netapp
6.5
2020-07-31 CVE-2020-5413 Deserialization of Untrusted Data vulnerability in multiple products
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization.
network
low complexity
vmware oracle CWE-502
7.5
2020-07-15 CVE-2020-14710 Unspecified vulnerability in Oracle Retail Customer Management and Segmentation Foundation 16.0/17.0/18.0
Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security).
network
low complexity
oracle
5.5
2020-07-15 CVE-2020-14709 Unspecified vulnerability in Oracle Retail Customer Management and Segmentation Foundation 16.0/17.0/18.0
Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Card).
network
low complexity
oracle
5.5
2020-07-15 CVE-2020-14708 Unspecified vulnerability in Oracle Retail Customer Management and Segmentation Foundation 16.0/17.0/18.0
Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment).
network
low complexity
oracle
4.0
2020-05-01 CVE-2020-10683 XXE vulnerability in multiple products
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks.
network
low complexity
dom4j-project oracle opensuse netapp canonical CWE-611
critical
9.8
2020-04-27 CVE-2020-9488 Improper Certificate Validation vulnerability in multiple products
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.
network
high complexity
apache oracle debian qos CWE-295
3.7
2020-04-15 CVE-2020-2953 Unspecified vulnerability in Oracle Retail Customer Management and Segmentation Foundation 18.0
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions).
network
low complexity
oracle
7.5
2020-01-15 CVE-2020-2567 Unspecified vulnerability in Oracle Retail Customer Management and Segmentation Foundation 18.0
Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security).
network
oracle
4.9
2019-11-08 CVE-2019-10219 Cross-site Scripting vulnerability in multiple products
A vulnerability was found in Hibernate-Validator.
network
low complexity
redhat netapp oracle CWE-79
6.1