Vulnerabilities > Oracle > Tuxedo > High

DATE CVE VULNERABILITY TITLE RISK
2022-01-18 CVE-2022-23302 Deserialization of Untrusted Data vulnerability in multiple products
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to.
network
low complexity
apache netapp broadcom qos oracle CWE-502
8.8
2022-01-18 CVE-2022-23307 Deserialization of Untrusted Data vulnerability in multiple products
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw.
network
low complexity
apache qos oracle CWE-502
8.8
2021-12-14 CVE-2021-4104 Deserialization of Untrusted Data vulnerability in multiple products
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration.
network
high complexity
apache fedoraproject redhat oracle CWE-502
7.5
2019-05-01 CVE-2019-0227 Server-Side Request Forgery (SSRF) vulnerability in multiple products
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006.
high complexity
apache oracle CWE-918
7.5
2018-07-18 CVE-2018-3007 Unspecified vulnerability in Oracle Tuxedo 12.1.1/12.1.3/12.2.2
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core).
network
low complexity
oracle
8.6
2017-11-14 CVE-2017-10278 Unspecified vulnerability in Oracle Tuxedo
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Security).
network
high complexity
oracle
7.0
2017-11-14 CVE-2017-10267 Information Exposure vulnerability in Oracle Tuxedo
Vulnerability in the Oracle Tuxedo component of Oracle Fusion Middleware (subcomponent: Core).
network
low complexity
oracle CWE-200
7.5