Oracle Vulnerabilities and Affected Products
Vulnerabilities associated with insurance_policy_administration_j2ee.
Products
Clear product- Advanced Outbound Telephony38 vulnerabilities
- Marketing23 vulnerabilities
- Java SE21 vulnerabilities
- WebLogic Server21 vulnerabilities
- One-to-One Fulfillment19 vulnerabilities
- weblogic_server19 vulnerabilities
- MySQL Server17 vulnerabilities
- communications_diameter_signaling_router13 vulnerabilities
- enterprise_manager_base_platform13 vulnerabilities
- FLEXCUBE Universal Banking13 vulnerabilities
- agile_plm12 vulnerabilities
- autovue_for_agile_product_lifecycle_management12 vulnerabilities
- banking_digital_experience12 vulnerabilities
- communications_calendar_server12 vulnerabilities
- communications_element_manager12 vulnerabilities
- communications_evolved_communications_application_server12 vulnerabilities
- communications_instant_messaging_server12 vulnerabilities
- communications_network_charging_and_control12 vulnerabilities
- communications_session_route_manager12 vulnerabilities
- financial_services_analytical_applications_infrastructure12 vulnerabilities
- financial_services_institutional_performance_analytics12 vulnerabilities
- financial_services_price_creation_and_discovery12 vulnerabilities
- financial_services_retail_customer_analytics12 vulnerabilities
- global_lifecycle_management_opatch12 vulnerabilities
- insurance_policy_administration_j2ee12 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-36179HIGH | Unsafe Deserialization in jackson-databindFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS. CWE-502Jan 6, 2021 | CVSS8.8v3.1 | EPSS20.9% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36180HIGH | Unsafe Deserialization in jackson-databindFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS. CWE-502Jan 6, 2021 | CVSS8.8v3.1 | EPSS5.04% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36182HIGH | Unsafe Deserialization in jackson-databindFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS. CWE-502Jan 6, 2021 | CVSS8.8v3.1 | EPSS5.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36184HIGH | Unsafe Deserialization in jackson-databindFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource. CWE-502Jan 6, 2021 | CVSS8.8v3.1 | EPSS10.4% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-36181HIGH | Unsafe Deserialization in jackson-databindFasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS. CWE-502Jan 6, 2021 | CVSS8.8v3.1 | EPSS5.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11111HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms). CWE-502Mar 31, 2020 | CVSS8.8v3.1 | EPSS3.49% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11112HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). CWE-502Mar 31, 2020 | CVSS8.8v3.1 | EPSS3.58% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-11113HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). CWE-502Mar 31, 2020 | CVSS8.8v3.1 | EPSS6.28% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-10968HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy). CWE-502Mar 26, 2020 | CVSS8.8v3.1 | EPSS3.63% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-10969HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane. CWE-502Mar 26, 2020 | CVSS8.8v3.1 | EPSS3.56% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-10672HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms). CWE-502Mar 18, 2020 | CVSS8.8v3.1 | EPSS3.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-10673HIGH | jackson-databind mishandles the interaction between serialization gadgets and typingFasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus). CWE-502Mar 18, 2020 | CVSS8.8v3.1 | EPSS8.03% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |