CVE Vulnerabilities for "product:banking_supply_chain_finance"

Showing 1-10 of 26 CVEs (filtered from 316,547 total)

CVE-2022-22963
⚠️🧬

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CRITICAL 9.8
EPSS 94.5%
29 exploits
4/1/2022
2022

In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

MEDIUM 5.5
EPSS 0.0%
6/12/2021
2021

In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.

MEDIUM 5.5
EPSS 0.4%
6/12/2021
2021

XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types is affected. The vulnerability is patched in version 1.4.17.

HIGH 7.5
EPSS 90.8%
2 exploits
5/28/2021
2021

A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.

MEDIUM 5.5
EPSS 0.5%
3/19/2021
2021

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

HIGH 7.2
EPSS 0.7%
2/15/2021
2021

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

MEDIUM 5.3
EPSS 0.2%
1 exploit
2/15/2021
2020

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.

HIGH 8.1
EPSS 2.1%
1 exploit
1/7/2021
2020

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.

HIGH 8.1
EPSS 2.3%
1 exploit
1/7/2021
2020

FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.

HIGH 8.1
EPSS 2.2%
2 exploits
1/7/2021
2020
Page 1 of 2