Page 2 of 15 results (0.008 seconds)

CVSS: 9.8EPSS: 7%CPEs: 180EXPL: 1

26 Jul 2019 — initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. La función initDocumentParser en el archivo xml/XMLSchedulingDataProcessor.java en Quartz Scheduler de Terracotta hasta la versión 2.3.0, permite ataques de tipo XXE por medio de una descripción del trabajo. The Terracotta Quartz Scheduler is susceptible to an XML external entity attack (XXE) through a job description. This issue stems from inadequate handling of X... • https://github.com/epicosy/Quartz-1 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 9.0EPSS: 5%CPEs: 36EXPL: 0

21 Jul 2016 — Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle Documaker component in Oracle Insurance Applications before 12.5; the Oracle Insurance Calculation Engine componen... • http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html •

CVSS: 5.8EPSS: 0%CPEs: 1EXPL: 0

21 Jul 2016 — Unspecified vulnerability in the Oracle Retail Order Broker component in Oracle Retail Applications 15.0 allows remote attackers to affect confidentiality and integrity via vectors related to System Administration. Vulnerabilidad no especificada en el componente Oracle Retail Order Broker en Oracle Retail Applications 15.0 permite a atacantes remotos afectar la confidencialidad e integridad a través de vectores relacionados con System Administration. • http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html •

CVSS: 9.8EPSS: 0%CPEs: 2EXPL: 0

21 Jan 2016 — Unspecified vulnerability in the Oracle Retail Order Broker Cloud Service component in Oracle Retail Applications 4.0 and 4.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to System Administration. Vulnerabilidad no especificada en el componente Oracle Retail Order Broker Cloud Service en Oracle Retail Applications 4.0 y 4.1 permite a atacantes remotos afectar a la confidencialidad, la integridad y la disponibilidad a través de vectores desconocid... • http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html •

CVSS: 9.8EPSS: 52%CPEs: 120EXPL: 0

16 Jul 2015 — The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. Vulnerabilidad en la clase MethodClosure en runtime/MethodClosure.java en Apache Groovy desde la versión 1.7.0 hasta la versión 2.4.3, permite a atacantes remotos ejecutar código arbitrario y causar una denegación de servicio a través de un objeto serializado manipulado. A flaw was discovered in the way appl... • http://groovy-lang.org/security.html • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-284: Improper Access Control •