HIGH✓ PATCH🇬🇧 English

CVE-2021-23337

CVSS 7.2v3.1pub. 2021-02-15upd. 2024-11-21

Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Lodash

    APP
    Lodash
    < 4.17.21
  • Netapp Active Iq Unified Manager

    APP
    Netapp
    wszystkie wersje
  • Netapp Cloud Manager

    APP
    Netapp
    wszystkie wersje
  • Netapp System Manager

    APP
    Netapp
    9.0
  • Oracle Banking Corporate Lending Process Management

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Banking Credit Facilities Process Management

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Banking Extensibility Workbench

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Banking Supply Chain Finance

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Banking Trade Finance Process Management

    APP
    Oracle
    14.2.014.3.014.5.0
  • Oracle Communications Cloud Native Core Binding Support Function

    APP
    Oracle
    1.9.0
  • Oracle Communications Cloud Native Core Policy

    APP
    Oracle
    1.11.0
  • Oracle Communications Design Studio

    APP
    Oracle
    7.4.2.0.0
  • Oracle Communications Services Gatekeeper

    APP
    Oracle
    7.0
  • Oracle Communications Session Border Controller

    APP
    Oracle
    8.49.0
  • Oracle Enterprise Communications Broker

    APP
    Oracle
    3.2.03.3.0
  • Oracle Financial Services Crime And Compliance Management Studio

    APP
    Oracle
    8.0.8.2.08.0.8.3.0
  • Oracle Health Sciences Data Management Workbench

    APP
    Oracle
    2.5.2.13.0.0.0
  • Oracle Jd Edwards Enterpriseone Tools

    APP
    Oracle
    < 9.2.6.1
  • Oracle Peoplesoft Enterprise Peopletools

    APP
    Oracle
    8.588.59
  • Oracle Primavera Gateway

    APP
    Oracle
    20.12.0 – 20.12.717.12.0 – 17.12.1118.8.0 – 18.8.1219.12.0 – 19.12.11
  • Oracle Primavera Unifier

    APP
    Oracle
    18.819.1220.1217.7 – 17.12
  • Oracle Retail Customer Management And Segmentation Foundation

    APP
    Oracle
    19.0
  • Siemens Sinec Ins

    APP
    Siemens
    1.0< 1.0
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-35273CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Pominięcie uwierzytelnienia w Oracle PeopleSoft PeopleTools (RCE/Takeover)

CVE-2022-22963CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Spring Cloud Function poprzez złośliwy SpEL routing-expression

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2022-22947CRITICAL10.0⚠ KEVPL ✓ten sam produkt

RCE poprzez code injection w VMware Spring Cloud Gateway (Actuator endpoint)

CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓ten sam produkt

Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup