This project will be discontinued after December 13, 2021. [more]
Product:
Endeca_information_discovery_integrator
(Oracle)
Repositories
Unknown:
This might be proprietary software.
#Vulnerabilities
12
Date
Id
Summary
Products
Score
Patch
Annotated
2018-05-11
CVE-2018-1258
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Vulnerability in the Oracle Endeca Information Discovery Integrator component of Oracle Fusion Middleware (subcomponent: Integrator ETL). Supported versions that are affected are 3.1.0 and 3.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Endeca Information Discovery Integrator. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in...