Loading product vulnerabilities…
Total
3
Critical
0
High
0
Medium
3
CISA KEV
0
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
User’s supplied input (usually a CRLF sequence) can be used to split a returning response into two responses.
An authenticated user can supply malicious HTML and JavaScript code that will be executed in the client browser.