Known vulnerabilities in Oracle Financial Services Price Creation and Discovery
Vendor:
Oracle
Software CPE:
cpe:2.3:a:oracle:oracle_financial_services_price_creation_and_discovery:*:*:*:*:*:*:*:*
Website:
https://www.oracle.com
Total vulnerabilities:
6
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU27487 - Improper Certificate Validation CVE-2020-9488 |
CWE-295 | Low | - | 04.05.2020 |
SB2020050406 SB2020071606 SB2020071620 and 67 more |
||
| #VU27206 - Improper input validation CVE-2020-2942 |
CWE-20 | Medium | - | 23.04.2020 |
SB2020041469 |
||
| #VU27052 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2020-11022 |
CWE-79 | Low | - | 21.04.2020 |
SB2020042126 SB2020052033 SB2020052103 and 181 more |
||
| #VU25830 - Deserialization of Untrusted Data CVE-2020-9546 |
CWE-502 | High | - | 09.03.2020 |
SB2020030909 SB2020071523 SB2020071620 and 31 more |
||
| #VU18092 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2019-11358 |
CWE-1321 | Low | - | 28.03.2019 |
SB2019032804 SB2019041026 SB2019041801 and 155 more |
||
| #VU17781 - Improper input validation CVE-2018-19362 |
CWE-20 | High | - | 19.02.2019 |
SB2018121501 SB2019052407 SB2019091718 and 38 more |