|
CVE-2014-8890
|
Medium
|
2014-12-18
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server Liberty Profile 8.5.x before 8.5.5.4 allows remote attackers to gain privileges by leveraging the combination of a servlet's deployment descriptor security constraints and ServletSecurity annotations.
|
|
CVE-2014-6174
|
Medium
|
2014-12-18
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to conduct clickjacking attacks via a crafted web site.
|
|
CVE-2014-6167
|
Medium
|
2014-12-18
|
No fix identified
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the URL rewriting feature in IBM WebSphere Application Server 7.x before 7.0.0.37, 8.0.x before 8.0.0.10, and 8.5.x before 8.5.5.4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
|
CVE-2014-6166
|
Medium
|
2014-12-18
|
Protected by RASP
|
No public exploit
|
The Communications Enabled Applications (CEA) service in IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4, and Feature Pack for CEA 1.x before 1.0.0.15, allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
|
|
CVE-2014-6164
|
Medium
|
2014-12-18
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server 8.0.x before 8.0.0.10 and 8.5.x before 8.5.5.4 allows remote attackers to spoof OpenID and OpenID Connect cookies, and consequently obtain sensitive information, via a crafted URL.
|
|
CVE-2014-7852
|
Medium
|
2014-12-11
|
No fix identified
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in JBoss RichFaces, as used in JBoss Portal 6.1.1, allows remote attackers to inject arbitrary web script or HTML via crafted URL, which is not properly handled in a CSS file.
|
|
CVE-2014-3627
|
Medium
|
2014-12-05
|
No exploit published
|
No public exploit
|
The YARN NodeManager daemon in Apache Hadoop 0.23.0 through 0.23.11 and 2.x before 2.5.2, when using Kerberos authentication, allows remote cluster users to change the permissions of certain files to world-readable via a symlink attack in a public tar archive, which is not properly handled during localization, related to distributed cache.
|
|
CVE-2014-7816
|
Medium
|
2014-12-01
|
Protected by RASP
|
No public exploit
|
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.
|
|
CVE-2014-7839
|
Medium
|
2014-11-25
|
Protected by RASP
|
No public exploit
|
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.
|
|
CVE-2014-5326
|
Medium
|
2014-11-24
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
|
CVE-2014-5325
|
Medium
|
2014-11-24
|
Protected by RASP
|
No public exploit
|
The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
|
|
CVE-2014-3625
|
Medium
|
2014-11-20
|
Protected by RASP
|
Proof of concept only
|
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
|
|
CVE-2014-0059
|
Low
|
2014-11-17
|
No fix identified
|
No public exploit
|
JBoss SX and PicketBox, as used in Red Hat JBoss Enterprise Application Platform (EAP) before 6.2.3, use world-readable permissions on audit.log, which allows local users to obtain sensitive information by reading this file.
|
|
CVE-2014-0228
|
Low
|
2014-11-16
|
No exploit published
|
No public exploit
|
Apache Hive before 0.13.1, when in SQL standards based authorization mode, does not properly check the file permissions for (1) import and (2) export statements, which allows remote authenticated users to obtain sensitive information via a crafted URI.
|
|
CVE-2014-3623
|
Medium
|
2014-10-30
|
No exploit published
|
No public exploit
|
Apache WSS4J before 1.6.17 and 2.x before 2.0.2, as used in Apache CXF 2.7.x before 2.7.13 and 3.0.x before 3.0.2, when using TransportBinding, does not properly enforce the SAML SubjectConfirmation method security semantics, which allows remote attackers to conduct spoofing attacks via unspecified vectors.
|
|
CVE-2014-3584
|
Medium
|
2014-10-30
|
No exploit published
|
No public exploit
|
The SamlHeaderInHandler in Apache CXF before 2.6.11, 2.7.x before 2.7.8, and 3.0.x before 3.0.1 allows remote attackers to cause a denial of service (infinite loop) via a crafted SAML token in the authorization header of a request to a JAX-RS service.
|
|
CVE-2014-5075
|
Medium
|
2014-10-25
|
No fix identified
|
No public exploit
|
The Ignite Realtime Smack XMPP API 4.x before 4.0.2, and 3.x and 2.x when a custom SSLContext is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
|
|
CVE-2014-3604
|
Medium
|
2014-10-25
|
No exploit published
|
No public exploit
|
Certificates.java in Not Yet Commons SSL before 0.3.15 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
|
|
CVE-2014-3021
|
Medium
|
2014-10-19
|
No fix identified
|
No public exploit
|
IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 does not properly handle HTTP headers, which allows remote attackers to obtain sensitive cookie and authentication data via an unspecified HTTP method.
|
|
CVE-2014-2068
|
Low
|
2014-10-17
|
No exploit published
|
No public exploit
|
The doIndex function in hudson/util/RemotingDiagnostics.java in CloudBees Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users with the ADMINISTER permission to obtain sensitive information via vectors related to heapDump.
|
|
CVE-2014-2066
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
Session fixation vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack web sessions via vectors involving the "override" of Jenkins cookies.
|
|
CVE-2014-2065
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.
|
|
CVE-2014-2064
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
The loadUserByUsername function in hudson/security/HudsonPrivateSecurityRealm.java in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to determine whether a user exists via vectors related to failed login attempts.
|
|
CVE-2014-2063
|
High
|
2014-10-17
|
No exploit published
|
No public exploit
|
Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
|
CVE-2014-2062
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is deleted, which allows remote authenticated users to retain access via the token.
|
|
CVE-2014-2061
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
The input control in PasswordParameterDefinition in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to obtain passwords by reading the HTML source code, related to the default value.
|
|
CVE-2014-2060
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
The Winstone servlet container in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to hijack sessions via unspecified vectors.
|
|
CVE-2014-2058
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.
|
|
CVE-2013-7330
|
Medium
|
2014-10-17
|
No exploit published
|
No public exploit
|
Jenkins before 1.502 allows remote authenticated users to configure an otherwise restricted project via vectors related to post-build actions.
|
|
CVE-2014-3680
|
Medium
|
2014-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/READ permission to obtain the default value for the password field of a parameterized job by reading the DOM.
|
|
CVE-2014-3679
|
Medium
|
2014-10-16
|
No exploit published
|
No public exploit
|
The Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to obtain sensitive information by accessing unspecified pages.
|
|
CVE-2014-3667
|
Medium
|
2014-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.583 and LTS before 1.565.3 does not properly prevent downloading of plugins, which allows remote authenticated users with the Overall/READ permission to obtain sensitive information by reading the plugin code.
|
|
CVE-2014-3666
|
High
|
2014-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
|
|
CVE-2014-3663
|
Medium
|
2014-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Job/CONFIGURE permission to bypass intended restrictions and create or destroy arbitrary jobs via unspecified vectors.
|
|
CVE-2014-3662
|
Medium
|
2014-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to enumerate user names via vectors related to login attempts.
|
|
CVE-2014-3661
|
Medium
|
2014-10-16
|
No exploit published
|
No public exploit
|
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to cause a denial of service (thread consumption) via vectors related to a CLI handshake.
|
|
CVE-2014-6562
|
High
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
|
|
CVE-2014-6561
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Payments component in Oracle E-Business Suite 12.0.4, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via unknown vectors related to Separate Remittance Advice.
|
|
CVE-2014-6558
|
Low
|
2014-10-15
|
Mitigation candidate
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and JRockit R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Security.
|
|
CVE-2014-6557
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Application Performance Management component in Oracle Enterprise Manager Grid Control before 12.1.0.6.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to End User Experience Management.
|
|
CVE-2014-6554
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Admin Console.
|
|
CVE-2014-6553
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5 and 11.1.1.7 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Admin Console.
|
|
CVE-2014-6552
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors related to Admin Console.
|
|
CVE-2014-6550
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to iHelp.
|
|
CVE-2014-6543
|
Low
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect confidentiality and integrity via vectors related to ITEM (Item & BOM).
|
|
CVE-2014-6539
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to LOV, a different vulnerability than CVE-2014-6472.
|
|
CVE-2014-6536
|
Low
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.3 allows remote authenticated users to affect integrity via unknown vectors related to Security.
|
|
CVE-2014-6535
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52, 8.53, and 8.54 allows remote attackers to affect confidentiality and integrity via vectors related to SECURITY.
|
|
CVE-2014-6534
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote authenticated users to affect integrity via vectors related to WLS Console.
|
|
CVE-2014-6533
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1 and 6.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Security.
|
|
CVE-2014-6531
|
Medium
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Libraries.
|
|
CVE-2014-6523
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality via vectors related to REST Interface.
|
|
CVE-2014-6522
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7, 11.1.2.4, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect integrity via vectors related to ADF Faces.
|
|
CVE-2014-6519
|
Medium
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 7u67 and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect integrity via unknown vectors related to Hotspot.
|
|
CVE-2014-6517
|
Medium
|
2014-10-15
|
Protected by RASP
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and Jrockit R27.8.3 and R28.3.3 allows remote attackers to affect confidentiality via vectors related to JAXP.
|
|
CVE-2014-6516
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 8.98 allows local users to affect confidentiality, integrity, and availability via vectors related to Installation SEC.
|
|
CVE-2014-6513
|
High
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT.
|
|
CVE-2014-6512
|
Medium
|
2014-10-15
|
Mitigation candidate
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20; Java SE Embedded 7u60; and JRockit R27.8.3 and R28.3.3 allows remote attackers to affect integrity via unknown vectors related to Libraries.
|
|
CVE-2014-6511
|
Medium
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20 allows remote attackers to affect confidentiality via unknown vectors related to 2D.
|
|
CVE-2014-6508
|
High
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows remote attackers to affect availability via vectors related to iSCSI Data Mover (IDM).
|
|
CVE-2014-6506
|
Medium
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries.
|
|
CVE-2014-6504
|
Medium
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, and 7u67, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality via unknown vectors related to Hotspot.
|
|
CVE-2014-6502
|
Low
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 5.0u71, 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect integrity via unknown vectors related to Libraries.
|
|
CVE-2014-6499
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, 12.1.2.0, and 12.1.3.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to WebLogic Tuxedo Connector.
|
|
CVE-2014-6498
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply Chain Products Suite 6.1, 6.2, 6.3, 6.3.1, 6.3.2, 6.3.3, 6.3.4, and 6.3.5 allows remote attackers to affect confidentiality via unknown vectors related to Security.
|
|
CVE-2014-6487
|
Low
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.1.2.1, and 11.1.2.2 allows remote authenticated users to affect integrity via unknown vectors related to End User Self Service.
|
|
CVE-2014-6486
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.2 allows remote authenticated users to affect integrity via unknown vectors related to Talent Acquisition Manager - Security.
|
|
CVE-2014-6485
|
High
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 8u20 and JavaFX 2.2.65 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
|
CVE-2014-6482
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PT PeopleTools component in Oracle PeopleSoft Products 8.53 and 8.54 allows remote authenticated users to affect integrity via unknown vectors related to Updates Change Assistant.
|
|
CVE-2014-6479
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Technology component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality via vectors related to OC4J Configuration.
|
|
CVE-2014-6475
|
Low
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52, 8.53, and 8.54 allows remote authenticated users to affect confidentiality via unknown vectors related to Security.
|
|
CVE-2014-6472
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to LOV, a different vulnerability than CVE-2014-6539.
|
|
CVE-2014-6471
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via vectors related to OAM Diagnostics.
|
|
CVE-2014-6468
|
Medium
|
2014-10-15
|
Mitigation candidate
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 8u20 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
|
|
CVE-2014-6465
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Communications Session Border Controller component in Oracle Communications Applications SCX640m5 allows remote authenticated users to affect availability via unknown vectors related to Lawful Intercept.
|
|
CVE-2014-6462
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1.2.1 and 11.1.2.2 allows remote attackers to affect integrity via unknown vectors related to Admin Console.
|
|
CVE-2014-6461
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Agile PLM component in Oracle Supply Chain Products Suite 9.3.1.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Roles & Privileges.
|
|
CVE-2014-6460
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52, 8.53, and 8.54 allows remote authenticated users to affect confidentiality and integrity via vectors related to QUERY.
|
|
CVE-2014-6456
|
High
|
2014-10-15
|
Mitigated by environment configuration
|
No public exploit
|
Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
|
|
CVE-2014-4285
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Technology component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to Reports Configuration.
|
|
CVE-2014-4281
|
Medium
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Portal Integration.
|
|
CVE-2014-4278
|
High
|
2014-10-15
|
No fix identified
|
No public exploit
|
Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Oracle Forms.
|
|
CVE-2014-3681
|
Medium
|
2014-10-15
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
|
CVE-2014-3664
|
Medium
|
2014-10-15
|
Protected by RASP
|
No public exploit
|
Directory traversal vulnerability in Jenkins before 1.583 and LTS before 1.565.3 allows remote authenticated users with the Overall/READ permission to read arbitrary files via unspecified vectors.
|
|
CVE-2014-6439
|
Medium
|
2014-10-10
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the CORS functionality in Elasticsearch before 1.4.0.Beta1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
|
CVE-2014-3678
|
Medium
|
2014-10-10
|
No exploit published
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
|
CVE-2014-1868
|
Medium
|
2014-10-06
|
Protected by RASP
|
No public exploit
|
Restlet Framework 2.1.x before 2.1.7 and 2.x.x before 2.2 RC1, when using XMLRepresentation or XML serializers, allows attackers to cause a denial of service via an XML Entity Expansion (XEE) attack.
|
|
CVE-2014-0168
|
Medium
|
2014-10-06
|
No exploit published
|
No public exploit
|
Cross-site request forgery (CSRF) vulnerability in Jolokia before 1.2.1 allows remote attackers to hijack the authentication of users for requests that execute MBeans methods via a crafted web page.
|
|
CVE-2014-0074
|
High
|
2014-10-06
|
No fix identified
|
No public exploit
|
Apache Shiro 1.x before 1.2.3, when using an LDAP server with unauthenticated bind enabled, allows remote attackers to bypass authentication via an empty (1) username or (2) password.
|
|
CVE-2014-3558
|
Medium
|
2014-09-30
|
No exploit published
|
No public exploit
|
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
|
|
CVE-2014-0170
|
Medium
|
2014-09-30
|
Protected by RASP
|
No public exploit
|
Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue.
|
|
CVE-2014-4816
|
Medium
|
2014-09-23
|
No fix identified
|
No public exploit
|
Cross-site request forgery (CSRF) vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.
|
|
CVE-2014-4770
|
Low
|
2014-09-23
|
No fix identified
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.x through 6.1.0.47, 7.0 before 7.0.0.35, 8.0 before 8.0.0.10, and 8.5 before 8.5.5.4 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.
|
|
CVE-2013-4444
|
Medium
|
2014-09-12
|
No exploit published
|
No public exploit
|
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
|
|
CVE-2014-4758
|
Medium
|
2014-09-04
|
No fix identified
|
No public exploit
|
IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.x allow remote authenticated users to bypass intended access restrictions and send requests to internal services via a callService URL.
|
|
CVE-2014-3574
|
Medium
|
2014-09-04
|
No exploit published
|
No public exploit
|
Apache POI before 3.10.1 and 3.11.x before 3.11-beta2 allows remote attackers to cause a denial of service (CPU consumption and crash) via a crafted OOXML file, aka an XML Entity Expansion (XEE) attack.
|
|
CVE-2014-3529
|
Medium
|
2014-09-04
|
Protected by RASP
|
No public exploit
|
The OPC SAX setup in Apache POI before 3.10.1 allows remote attackers to read arbitrary files via an OpenXML file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
|
|
CVE-2014-3075
|
Low
|
2014-09-04
|
No fix identified
|
No public exploit
|
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 8.5.5 and WebSphere Lombardi Edition 7.2.0.x allows remote authenticated users to inject arbitrary web script or HTML via an uploaded file.
|
|
CVE-2012-6153
|
Medium
|
2014-09-04
|
Protected by RASP
|
No public exploit
|
http/conn/ssl/AbstractVerifier.java in Apache Commons HttpClient before 4.2.3 does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5783.
|
|
CVE-2014-3596
|
Medium
|
2014-08-27
|
No exploit published
|
No public exploit
|
The getCN function in Apache Axis 1.4 and earlier does not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a certificate with a subject that specifies a common name in a field that is not the CN field. NOTE: this issue exists because of an incomplete fix for CVE-2012-5784.
|