HIGH🇬🇧 English

CVE-2020-7712

CVSS 7.2v3.1pub. 2020-08-30upd. 2024-11-21

This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Joyent Json

    APP
    Joyent
    < 10.0.0
  • Oracle Commerce Guided Search

    APP
    Oracle
    11.3.2
  • Oracle Financial Services Crime And Compliance Management Studio

    APP
    Oracle
    8.0.8.2.08.0.8.3.0
  • Oracle Financial Services Regulatory Reporting With Agilereporter

    APP
    Oracle
    8.0.9.6.3
  • Oracle Timesten In Memory Database

    APP
    Oracle
    < 21.1.1.1.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓ten sam produkt

RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)

CVE-2018-1273CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Spring Data Commons — podatność property bindera

CVE-2026-70981CRITICAL9.1ten sam produkt

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...

CVE-2026-70980CRITICAL9.0ten sam produkt

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...

CVE-2026-70984CRITICAL9.1ten sam produkt

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Comm...