
CVE-2019-10219 – hibernate-validator: safeHTML validator allows XSS
https://notcve.org/view.php?id=CVE-2019-10219
08 Nov 2019 — A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. Una vulnerabilidad fue encontrada en Hibernate-Validator. La anotación del validador SafeHtml no puede sanear apropiadamente las cargas útiles que consisten en código potencialmente malicioso en los comentarios e instrucciones HTML. • https://access.redhat.com/errata/RHSA-2020:0159 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2015-2618
https://notcve.org/view.php?id=CVE-2015-2618
16 Jul 2015 — Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors related to Input validation. Vulnerabilidad no especificada en el componente Oracle Application Object Library en Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3 y 12.2.4, permite a usuarios remotos autenticados afectar la integridad a través de vectores desconocidos relacionad... • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html •

CVE-2015-2630 – Oracle E-Business Suite Open Redirection
https://notcve.org/view.php?id=CVE-2015-2630
16 Jul 2015 — Unspecified vulnerability in the Technology stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Applet startup. Vulnerabilidad no especificada en el componente de pila Technology en Oracle E-Business Suite 11.5.10.2, 12.0.6 y 12.1.3, permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con Applet startup. Oracle E-Business Suite is prone to a remote URL-redirection vuln... • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html •

CVE-2015-2645
https://notcve.org/view.php?id=CVE-2015-2645
16 Jul 2015 — Unspecified vulnerability in the Oracle Web Applications Desktop Integrator component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote authenticated users to affect integrity via unknown vectors. Vulnerabilidad no especificada en el componente Oracle Web Applications Desktop Integrator en Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3 y 12.2.4, permite a usuarios remotos autenticados afectar la integridad a través de vectores desconocidos. • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html •

CVE-2015-2652
https://notcve.org/view.php?id=CVE-2015-2652
16 Jul 2015 — Unspecified vulnerability in the Oracle Marketing component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Web Management. Vulnerabilidad no especificada en el componente Oracle Marketing en Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.3 y 12.2.4, permite a atacantes remotos afectar la integridad a través de vectores desconocidos relacionados con Web Management. • http://seclists.org/fulldisclosure/2015/Oct/33 •

CVE-2015-4739
https://notcve.org/view.php?id=CVE-2015-4739
16 Jul 2015 — Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote authenticated users to affect integrity via unknown vectors related to Help screens. Vulnerabilidad no especificada en el componente Oracle Application Object Library en Oracle E-Business Suite 11.5.10.2, permite a usuarios remotos autenticados afectar la integridad a través de vectores desconocidos relacionados con Help screens. • http://www.oracle.com/technetwork/topics/security/cpujul2015-2367936.html •

CVE-2008-3988
https://notcve.org/view.php?id=CVE-2008-3988
14 Oct 2008 — Unspecified vulnerability in the iSupplier Portal component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote attackers to affect confidentiality via unknown vectors. Vulnerabilidad no especificadas en el componente iSupplier Portal en Oracle E-Business Suite v11.5.10.2 y v12.0.4 permite a atacantes remotos afectar a la confidencialidad a través de vectores desconocidos. • http://secunia.com/advisories/32291 •

CVE-2008-3993
https://notcve.org/view.php?id=CVE-2008-3993
14 Oct 2008 — Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2 and 12.0.4 allows remote authenticated users to affect integrity via unknown vectors. Vulnerabilidad no especificada en el componente Oracle Applications Framework component en Oracle E-Business Suite v11.5.10.2 y v12.0.4 permite a usuarios remotos autenticados afectar a la integridad a través de vectores desconocidos. • http://secunia.com/advisories/32291 •

CVE-2006-1884
https://notcve.org/view.php?id=CVE-2006-1884
20 Apr 2006 — Unspecified vulnerability in the Oracle Thesaurus Management System component in Oracle E-Business Suite and OPA 4.5.2 Applications has unknown impact and attack vectors, aka Vuln# OPA01. • http://secunia.com/advisories/19712 •

CVE-2005-3457
https://notcve.org/view.php?id=CVE-2005-3457
02 Nov 2005 — Unspecified vulnerability in Oracle E-Business Suite and Applications 11.0 up to 11.5.10 has unknown impact and attack vectors, as identified by Oracle Vuln# APPS08 in HRMS. • http://secunia.com/advisories/17250 •