Vulnerabilities > Oracle > Solaris Cluster

DATE CVE VULNERABILITY TITLE RISK
2021-06-02 CVE-2020-6950 Path Traversal vulnerability in multiple products
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
4.3
2021-04-13 CVE-2021-29425 Path Traversal vulnerability in multiple products
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
network
high complexity
apache debian oracle netapp CWE-22
4.8
2019-10-15 CVE-2019-17195 Improper Handling of Exceptional Conditions vulnerability in multiple products
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
network
low complexity
connect2id apache oracle CWE-755
critical
9.8
2019-08-20 CVE-2019-10086 Deserialization of Untrusted Data vulnerability in multiple products
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects.
7.3
2018-07-18 CVE-2018-2930 Unspecified vulnerability in Oracle Solaris Cluster 3.3/4.3
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition).
network
low complexity
oracle
7.5
2018-04-19 CVE-2018-2822 Unspecified vulnerability in Oracle Solaris Cluster 4.3
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: Cluster Geo).
local
low complexity
oracle
4.6
2017-10-19 CVE-2017-3588 Unspecified vulnerability in Oracle Solaris Cluster 3.3/4.3
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: HA for MySQL).
local
oracle
4.4
2017-08-08 CVE-2017-10234 Unspecified vulnerability in Oracle Solaris Cluster 4.0
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition).
local
oracle
4.4
2017-04-24 CVE-2016-5551 Improper Access Control vulnerability in Oracle Solaris Cluster 4.3
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition).
local
oracle CWE-284
1.9
2016-10-25 CVE-2016-5525 Improper Access Control vulnerability in Oracle Solaris Cluster 3.3/4.3
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect integrity via vectors related to Cluster check files.
local
low complexity
oracle CWE-284
2.1