脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: タグ: weblogic-server クリア
ID タイトル
CVE-2018-2628 KEV 【KEV】Oracle weblogic-server に 安全でないデシリアライゼーション (CVE-2018-2628)
Oracle weblogic-server に 脆弱性 (CVE-2018-2628) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2017-10271 KEV 【KEV】Oracle weblogic-server の脆弱性 (CVE-2017-10271)
Oracle weblogic-server に 脆弱性 (CVE-2017-10271) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2022-23437 apache の脆弱性 (CVE-2022-23437)
apache に 脆弱性 (CVE-2022-23437) が存在。不正な操作・情報露出のリスクがあります。
CVE-2022-23302 apache に 安全でないデシリアライゼーション (CVE-2022-23302)
apache に 脆弱性 (CVE-2022-23302) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2022-23307 apache に 安全でないデシリアライゼーション (CVE-2022-23307)
apache に 脆弱性 (CVE-2022-23307) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2022-23305 log4j:log4j に SQLインジェクション (CVE-2022-23305)
log4j:log4j に SQLインジェクション (CVE-2022-23305) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2019-2725 KEV 【KEV】Oracle weblogic-server の脆弱性 (CVE-2019-2725)
Oracle weblogic-server に 脆弱性 (CVE-2019-2725) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2021-44832 org.apache.logging.log4j:log4j-core の脆弱性 (CVE-2021-44832)
org.apache.logging.log4j:log4j-core に 脆弱性 (CVE-2021-44832) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `2.17.1` 以上に更新。
CVE-2021-45105 org.apache.logging.log4j:log4j-core の脆弱性 (CVE-2021-45105)
org.apache.logging.log4j:log4j-core に 脆弱性 (CVE-2021-45105) が存在。不正な操作・情報露出のリスクがあります。対策: `2.3.1` 以上に更新。
CVE-2021-4104 apache に 安全でないデシリアライゼーション (CVE-2021-4104)
apache に 脆弱性 (CVE-2021-4104) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2015-4852 KEV 【KEV】Oracle weblogic-server に 安全でないデシリアライゼーション (CVE-2015-4852)
Oracle weblogic-server に 脆弱性 (CVE-2015-4852) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2020-14750 KEV 【KEV】Oracle weblogic-server の脆弱性 (CVE-2020-14750)
Oracle weblogic-server に 脆弱性 (CVE-2020-14750) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2020-14882 KEV 【KEV】Oracle weblogic-server の脆弱性 (CVE-2020-14882)
Oracle weblogic-server に 脆弱性 (CVE-2020-14882) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2020-14883 KEV 【KEV】Oracle weblogic-server の脆弱性 (CVE-2020-14883)
Oracle weblogic-server に 脆弱性 (CVE-2020-14883) が存在。不正な操作・情報露出のリスクがあります。CISA KEV登録済 — 実環境で悪用が確認されている。
CVE-2021-41182 jqueryui に クロスサイトスクリプティング (CVE-2021-41182)
jqueryui に XSS (クロスサイトスクリプティング) (CVE-2021-41182) が存在。データの不正な改ざんを許す可能性があります。``altField`` 経由で攻撃可能。
CVE-2021-41183 c に クロスサイトスクリプティング (CVE-2021-41183)
c に XSS (クロスサイトスクリプティング) (CVE-2021-41183) が存在。データの不正な改ざんを許す可能性があります。
CVE-2021-41184 jqueryui に クロスサイトスクリプティング (CVE-2021-41184)
jqueryui に XSS (クロスサイトスクリプティング) (CVE-2021-41184) が存在。データの不正な改ざんを許す可能性があります。
CVE-2021-40690 apache に 情報漏洩 (CVE-2021-40690)
apache に 脆弱性 (CVE-2021-40690) が存在。機密情報が外部に流出する可能性があります。
CVE-2021-2351 Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unau...
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Su...
CVE-2021-29425 apache の脆弱性 (CVE-2021-29425)
apache に 脆弱性 (CVE-2021-29425) が存在。不正な操作・情報露出のリスクがあります。
CVE-2020-9488 org.apache.logging.log4j:log4j の脆弱性 (CVE-2020-9488)
org.apache.logging.log4j:log4j に 脆弱性 (CVE-2020-9488) が存在。不正な操作・情報露出のリスクがあります。対策: `2.3.2` 以上に更新。
CVE-2020-11619 fasterxml に 安全でないデシリアライゼーション (CVE-2020-11619)
fasterxml に 脆弱性 (CVE-2020-11619) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2020-9548 fasterxml に 安全でないデシリアライゼーション (CVE-2020-9548)
fasterxml に 脆弱性 (CVE-2020-9548) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2020-9546 apache に 安全でないデシリアライゼーション (CVE-2020-9546)
apache に 脆弱性 (CVE-2020-9546) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2019-17571 log4j:log4j に 安全でないデシリアライゼーション (CVE-2019-17571)
log4j:log4j に 脆弱性 (CVE-2019-17571) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2019-10219 redhat に クロスサイトスクリプティング (CVE-2019-10219)
redhat に XSS (クロスサイトスクリプティング) (CVE-2019-10219) が存在。不正な操作・情報露出のリスクがあります。
CVE-2019-10086 apache に 安全でないデシリアライゼーション (CVE-2019-10086)
apache に 脆弱性 (CVE-2019-10086) が存在。不正な操作・情報露出のリスクがあります。
CVE-2018-15756 spring の脆弱性 (CVE-2018-15756)
spring に 脆弱性 (CVE-2018-15756) が存在。不正な操作・情報露出のリスクがあります。
CVE-2018-11039 spring の脆弱性 (CVE-2018-11039)
spring に 脆弱性 (CVE-2018-11039) が存在。機密情報が外部に流出する可能性があります。
CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
CVE-2017-15707 apache の脆弱性 (CVE-2017-15707)
apache に 脆弱性 (CVE-2017-15707) が存在。不正な操作・情報露出のリスクがあります。
CVE-2016-8610 dos の脆弱性 (CVE-2016-8610)
dos に 脆弱性 (CVE-2016-8610) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10352 c の脆弱性 (CVE-2017-10352)
c に 脆弱性 (CVE-2017-10352) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10334 c に 情報漏洩 (CVE-2017-10334)
c に 脆弱性 (CVE-2017-10334) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10336 c の脆弱性 (CVE-2017-10336)
c に 脆弱性 (CVE-2017-10336) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10152 c に 情報漏洩 (CVE-2017-10152)
c に 脆弱性 (CVE-2017-10152) が存在。機密情報が外部に流出する可能性があります。
CVE-2017-10178 c の脆弱性 (CVE-2017-10178)
c に 脆弱性 (CVE-2017-10178) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10123 c の脆弱性 (CVE-2017-10123)
c に 脆弱性 (CVE-2017-10123) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10137 c の脆弱性 (CVE-2017-10137)
c に 脆弱性 (CVE-2017-10137) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2017-10147 c の脆弱性 (CVE-2017-10147)
c に 脆弱性 (CVE-2017-10147) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10148 c の脆弱性 (CVE-2017-10148)
c に 脆弱性 (CVE-2017-10148) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-10063 c の脆弱性 (CVE-2017-10063)
c に 脆弱性 (CVE-2017-10063) が存在。不正な操作・情報露出のリスクがあります。
CVE-2017-3531 c の脆弱性 (CVE-2017-3531)
c に 脆弱性 (CVE-2017-3531) が存在。不正な操作・情報露出のリスクがあります。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →