Home/Product/oracle primavera unifier
Product

oracle primavera unifier

95 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-30126
>= 17.7 and <= 17.12
In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a den
5.5MEDIUM
CVE-2022-25169
>= 17.7 and <= 17.12
The BPG parser in versions of Apache Tika before 1.28.2 and 2.4.0 may allocate an unreasonable amount of memory on carefully craft
5.5MEDIUM
CVE-2020-36518
>= 17.0 and <= 17.12
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
7.5HIGH
CVE-2021-44832
all versions
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code
6.6MEDIUM
CVE-2021-45105
all versions
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from sel
5.9MEDIUM
CVE-2021-23450
>= 17.7 and <= 17.12
All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
7.5HIGH
CVE-2021-41184
>= 17.7 and <= 17.12
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the of option of the `.
6.5MEDIUM
CVE-2021-41182
>= 17.7 and <= 17.12
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the altField option of
6.5MEDIUM
CVE-2021-42575
>= 17.7 and <= 17.12
The OWASP Java HTML Sanitizer before 20211018.1 does not properly enforce policies associated with the SELECT, STYLE, and OPTION e
9.8CRITICAL
CVE-2021-38153
all versions
Some components in Apache Kafka use Arrays.equals to validate a password or key, which is vulnerable to timing attacks that make
5.9MEDIUM
CVE-2021-37714
all versions
jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vu
7.5HIGH
CVE-2021-2351
>= 17.7 and <= 17.12
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1
8.3HIGH
CVE-2021-36374
>= 17.7 and <= 17.12
When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of m
5.5MEDIUM
CVE-2021-36373
>= 17.7 and <= 17.12
When reading a specially crafted TAR archive an Apache Ant build can be made to allocate large amounts of memory that finally lead
5.5MEDIUM
CVE-2021-36090
>= 17.7 and <= 17.12
When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an ou
7.5HIGH
CVE-2021-35517
>= 17.7 and <= 17.12
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an ou
7.5HIGH
CVE-2021-35516
>= 17.7 and <= 17.12
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out
7.5HIGH
CVE-2021-35515
>= 17.7 and <= 17.12
When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infi
7.5HIGH
CVE-2021-31811
>= 17.7 and <= 17.12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apa
5.5MEDIUM
CVE-2021-29425
>= 17.7 and <= 17.12
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo",
4.8MEDIUM
CVE-2021-28657
>= 17.7 and <= 17.12
A carefully crafted or corrupt file may trigger an infinite loop in Tika's MP3Parser up to and including Tika 1.25. Apache Tika us
5.5MEDIUM
CVE-2021-3449
>= 17.7 and <= 17.12
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renego
5.9MEDIUM
CVE-2021-27906
>= 17.7 and <= 17.12
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version
5.5MEDIUM
CVE-2021-27807
>= 17.7 and <= 17.12
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22
5.5MEDIUM
CVE-2021-23337
>= 17.7 and <= 17.12
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
7.2HIGH
CVE-2020-28500
>= 17.7 and <= 17.12
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd
5.3MEDIUM
CVE-2020-36183
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36182
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36180
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36179
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oad
8.1HIGH
CVE-2020-36189
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-36188
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-36187
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36186
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36185
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36184
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-36181
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-35728
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com
8.1HIGH
CVE-2020-35460
>= 17.7 and <= 17.12
common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to
5.3MEDIUM
CVE-2020-8908
>= 17.7 and <= 17.12
A temp directory creation vulnerability exists in all versions of Guava, allowing an attacker with access to the machine to potent
3.3LOW
CVE-2020-17521
>= 17.7 and <= 17.12
Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of
5.5MEDIUM
CVE-2020-13956
>= 17.7 and <= 17.12
Apache HttpClient versions prior to version 4.5.13 and 5.0.3 can misinterpret malformed authority component in request URIs passed
5.3MEDIUM
CVE-2020-11979
>= 17.7 and <= 17.12
As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current u
7.5HIGH
CVE-2020-25020
>= 17.7 and <= 17.12
MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.
9.8CRITICAL
CVE-2020-14618
< 20.6
Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Mobile App). The supported versi
5.9MEDIUM
CVE-2020-14617
>= 17.7 and <= 17.12
Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform, Mobile App). Supported
5.7MEDIUM
CVE-2020-1945
>= 17.7 and <= 17.12
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.
6.3MEDIUM
CVE-2020-9488
all versions
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be in
3.7LOW
CVE-2020-9489
>= 17.7 and <= 17.12
A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause
5.5MEDIUM
CVE-2020-11620
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-11619
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.1HIGH
CVE-2020-11113
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.8HIGH
CVE-2020-11112
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.8HIGH
CVE-2020-11111
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.8HIGH
CVE-2020-10969
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to jav
8.8HIGH
CVE-2020-10968
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.8HIGH
CVE-2020-10673
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com
8.8HIGH
CVE-2020-10672
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
8.8HIGH
CVE-2020-5258
>= 17.7 and <= 17.12
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers t
7.7HIGH
CVE-2020-9548
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.
9.8CRITICAL
CVE-2020-9547
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com
9.8CRITICAL
CVE-2020-9546
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org
9.8CRITICAL
CVE-2019-20330
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.10.2 lacks certain net.sf.ehcache blocking.
9.8CRITICAL
CVE-2019-17558
>= 17.7 and <= 17.12
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A Velocity te
7.5HIGH
CVE-2019-10219
>= 17.7 and <= 17.12
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting
6.1MEDIUM
CVE-2019-12415
>= 17.7 and <= 17.12
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially cra
5.5MEDIUM
CVE-2019-16942
>= 17.7 and <= 17.12
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (eith
9.8CRITICAL
CVE-2019-14540
>= 17.7 and <= 17.12
A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10. It is related to com.zaxxer.hikari.HikariCo
9.8CRITICAL
CVE-2019-14379
>= 17.7 and <= 17.12
SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2 mishandles default typing when ehcache is used (because of net.
9.8CRITICAL
CVE-2019-13990
>= 17.7 and <= 17.12
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a jo
9.8CRITICAL
CVE-2019-0227
>= 17.7 and <= 17.12
A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Secur
7.5HIGH
CVE-2019-11358
>= 17.7 and <= 17.12
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Objec
6.1MEDIUM
CVE-2018-19362
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jb
9.8CRITICAL
CVE-2018-19361
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the op
9.8CRITICAL
CVE-2018-19360
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the ax
9.8CRITICAL
CVE-2018-14721
>= 17.1 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by
10.0CRITICAL
CVE-2018-14720
>= 17.1 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failu
9.8CRITICAL
CVE-2018-14719
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block
9.8CRITICAL
CVE-2018-14718
>= 17.7 and <= 17.12
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block
9.8CRITICAL
CVE-2018-3148
>= 17.1 and <= 17.12
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Web Access). Supporte
6.1MEDIUM
CVE-2018-8032
>= 17.7 and <= 17.12
Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.
6.1MEDIUM
CVE-2018-2969
all versions
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The supported
4.3MEDIUM
CVE-2018-2968
all versions
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported vers
6.5MEDIUM
CVE-2018-2967
all versions
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported vers
5.3MEDIUM
CVE-2018-2966
all versions
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). Supported vers
7.4HIGH
CVE-2018-2965
all versions
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Core). The supported
6.1MEDIUM
CVE-2017-7525
>= 17.1 and <= 17.12
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an un
9.8CRITICAL
CVE-2017-15095
>= 17.1 and <= 17.12
A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenti
9.8CRITICAL
CVE-2015-9251
>= 17.1 and <= 17.12
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the
6.1MEDIUM
CVE-2018-2620
all versions
Vulnerability in the Primavera Unifier component of Oracle Construction and Engineering Suite (subcomponent: Platform). Supported
8.1HIGH
CVE-2017-10150
all versions
Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions t
4.3MEDIUM
CVE-2017-10149
all versions
Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions t
4.8MEDIUM
CVE-2017-3501
all versions
Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform). Supported versions t
6.1MEDIUM
CVE-2016-7103
>= 16.0 and <= 16.2
Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or
6.1MEDIUM
CVE-2016-4055
>= 16.0 and <= 18.8.4
The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU co
6.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin