Known vulnerabilities in Oracle Financial Services Revenue Management and Billing 2.9

Vendor: Oracle
Version: 2.9
Software CPE: cpe:2.3:a:oracle:oracle_financial_services_revenue_management_and_billing:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 2
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Oracle Financial Services Revenue Management and Billing version 2.9 Oracle Financial Services Revenue Management and Billing 2.9 is affected by 8 vulnerabilities: 2 high, 5 medium, 1 low Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU67585 - Server-Side Request Forgery (SSRF)
CVE-2022-40146
CWE-918 Medium
Public exploit available
No
- 22.09.2022 SB2022092232
SB2023011763
SB2023011838
and 21 more
#VU65495 - Improper input validation
CVE-2022-34169
CWE-20 High
Public exploit available
No
- 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 137 more
#VU60527 - Resource exhaustion
CVE-2021-43859
CWE-400 Medium
No
No
- 11.02.2022 SB2022021102
SB2022021103
SB2022042250
and 26 more
#VU59965 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2022-23437
CWE-835 Medium
No
No
- 25.01.2022 SB2022012503
SB2022041946
SB2022042249
and 92 more
#VU54853 - Resource exhaustion
CVE-2021-36090
CWE-400 Medium
No
No
- 14.07.2021 SB2021071408
SB2021080809
SB2021100411
and 70 more
#VU54291 - Server-Side Request Forgery (SSRF)
CVE-2020-11988
CWE-918 Medium
No
No
- 21.06.2021 SB2021062143
SB2021062144
SB2021062145
and 15 more
#VU52252 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-29425
CWE-22 Low
No
No
- 15.04.2021 SB2021041510
SB2021081922
SB2021093016
and 121 more
#VU22545 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2019-12415
CWE-611 High
No
No
- 06.11.2019 SB2019110635
SB2020012308
SB2020012309
and 42 more