
CVE-2019-0227 – Apache Axis 1.4 - Remote Code Execution
https://notcve.org/view.php?id=CVE-2019-0227
10 Apr 2019 — A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversion repository, legacy users are encouraged to build from source. The successor to Axis 1.x is Axis2, the latest version is 1.7.9 and is not vulnerable to this issue. Una vulnerabilidad de tipo SSRF (Server Side Request Forgery) afectó a la distribución de Apache Axis 1.4 que fue lanzada por última vez en 2006. ... • https://packetstorm.news/files/id/152462 • CWE-918: Server-Side Request Forgery (SSRF) •

CVE-2018-8032
https://notcve.org/view.php?id=CVE-2018-8032
02 Aug 2018 — Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services. Apache Axis en versiones 1.x hasta la 1.4 (incluida) es vulnerable a un ataque de Cross-Site Scripting (XSS) en el servlet/services por defecto. • https://github.com/cairuojin/CVE-2018-8032 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2017-10161
https://notcve.org/view.php?id=CVE-2017-10161
19 Oct 2017 — Vulnerability in the Oracle Engineering Data Management component of Oracle Supply Chain Products Suite (subcomponent: Web Services Security). Supported versions that are affected are 6.1.3.0 and 6.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Engineering Data Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Engineering Data Management accessible data... • http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html •

CVE-2017-3730 – Bad (EC)DHE parameters cause a client crash
https://notcve.org/view.php?id=CVE-2017-3730
26 Jan 2017 — In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. En OpenSSL versión 1.1.0 anterior a 1.1.0d, si un servidor malicioso suministra parámetros incorrectos para un intercambio de claves DHE o ECDHE, entonces esto puede resultar en que el cliente intente desreferenciar un puntero NULL que conduce ... • https://packetstorm.news/files/id/140804 • CWE-476: NULL Pointer Dereference •

CVE-2016-8735 – Apache Tomcat Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2016-8735
18 Dec 2016 — Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types. La ejecución remota de código es posible con Apache Tomcat en versiones anteriores a 6.0.48, 7.x en versiones anteriores a 7.0.73, 8.x en versiones ... • http://rhn.redhat.com/errata/RHSA-2017-0457.html • CWE-502: Deserialization of Untrusted Data •

CVE-2016-5518
https://notcve.org/view.php?id=CVE-2016-5518
25 Oct 2016 — Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to webfileservices. Vulnerabilidad no especificada en el componente Oracle Agile Engineering Data Management en Oracle Supply Chain Products Suite 6.1.3.0 y 6.2.0.0 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vec... • http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html •

CVE-2016-3468
https://notcve.org/view.php?id=CVE-2016-3468
21 Jul 2016 — Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Install. Vulnerabilidad no especificada en el componente Oracle Agile Engineering Data Management en Oracle Supply Chain Products Suite 6.1.3.0 y 6.2.0.0 permite a atacantes remotos afectar la confidencialidad, la integridad y la disponibilidad a través de vectores re... • http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html •

CVE-2016-3428
https://notcve.org/view.php?id=CVE-2016-3428
21 Apr 2016 — Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.3.0 and 6.2.0.0 allows remote attackers to affect availability via vectors related to Engineering Communication Interface. Vulnerabilidad no especificada en el componente Oracle Agile Engineering Data Management en Oracle Supply Chain Products Suite 6.1.3.0 y 6.2.0.0 permite a atacantes remotos afectar a la disponibilidad a través de vectores relacionados con Engineering Communicatio... • http://www.oracle.com/technetwork/security-advisory/cpuapr2016v3-2985753.html •

CVE-2016-0497
https://notcve.org/view.php?id=CVE-2016-0497
21 Jan 2016 — Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows remote attackers to affect integrity via unknown vectors related to Web Client. Vulnerabilidad no especificada en el componente Oracle Agile Engineering Data Management en Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0 y 6.2.0.0 permite a atacantes remotos afectar a la integridad a través de vectores desconocidos relacionados con Web Client. • http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html •

CVE-2016-0498
https://notcve.org/view.php?id=CVE-2016-0498
21 Jan 2016 — Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0, and 6.2.0.0 allows local users to affect confidentiality via unknown vectors related to Install. Vulnerabilidad no especificada en el componente Oracle Agile Engineering Data Management en Oracle Supply Chain Products Suite 6.1.2.2, 6.1.3.0 y 6.2.0.0 permite a usuarios locales afectar a la confidencialidad a través de vectores desconocidos relacionados con Install. • http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html •