Flexcube Universal Banking
Vendor:
First CVE: Oct 25, 2016 · Active for 9 years
95
Total CVEs
More Total CVEs than 99% of tracked products
10.6
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Flexcube Universal Banking over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2016
9 years ago
Most Recent CVE
Jan 20, 2026
185 days ago
CVE Severity & Scoring
Flexcube Universal Banking95 CVEs
75%
21%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (4.2%)
Network89 (93.7%)
Unknown0 (0.0%)
Physical2 (2.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low81 (85.3%)
High14 (14.7%)
Unknown0 (0.0%)
User Interaction
None58 (61.1%)
Unknown0 (0.0%)
Required37 (38.9%)
Privileges Required
Low61 (64.2%)
High0 (0.0%)
None34 (35.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (95 CVEs).
95 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-45105MEDIUM Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker wit | Dec 18, 2021 | 5.9 | 76 | NO | NO |
CVE-2021-37714HIGH jsoup is a Java library for working with HTML. Those using jsoup versions prior to 1.14.2 to parse untrusted HTML or XML may be vulnerable to DOS attacks. If the parser is run on u | Aug 18, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-36090HIGH When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35516HIGH When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35515HIGH When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of | Jul 13, 2021 | 7.5 | 30 | NO | NO |
CVE-2021-35517HIGH When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This | Jul 13, 2021 | 7.5 | 29 | NO | NO |
CVE-2020-11987HIGH Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could | Feb 24, 2021 | 8.2 | 28 | NO | NO |
CVE-2016-5607HIGH Unspecified vulnerability in the Oracle FLEXCUBE Universal Banking component in Oracle Financial Services Applications 11.3.0, 11.4.0, 12.0.1 through 12.0.3, 12.1.0, and 12.2.0 all | Oct 25, 2016 | 8.8 | 28 | NO | NO |
CVE-2019-12399HIGH When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that | Jan 14, 2020 | 7.5 | 26 | NO | NO |
CVE-2018-2648HIGH Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are | Jan 18, 2018 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (95 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (95 CVEs).
Media Mentions
Signals from CVEs in this product scope (95 CVEs).
Top CNAs Publishing CVEs For Flexcube Universal Banking
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.5.0 | 10 | 6.4 | 2.2% | 0 | 0 |
| 14.5 | 8 | 6.8 | 19.3% | 0 | 0 |
| 14.4.0 | 1 | 7.5 | 3.9% | 0 | 0 |
| 14.1.0 | 9 | 6.0 | 1.7% | 0 | 0 |
| 14.0.0 | 13 | 6.1 | 1.6% | 0 | 0 |
| 12.4.0 | 26 | 6.4 | 2.3% | 0 | 0 |
| 12.4 | 2 | 7.5 | 11.8% | 0 | 0 |
| 12.3.0 | 32 | 6.2 | 1.4% | 0 | 0 |
| 12.2.0 | 46 | 6.0 | 1.5% | 0 | 0 |
| 12.1.0 | 46 | 6.0 | 1.5% | 0 | 0 |
| 12.0.3 | 49 | 5.9 | 1.5% | 0 | 0 |
| 12.0.2 | 49 | 5.9 | 1.5% | 0 | 0 |
| 12.0.1 | 52 | 5.8 | 1.5% | 0 | 0 |
| 12.0.0 | 3 | 6.1 | 1.3% | 0 | 0 |
| 11.83.3 | 1 | 5.9 | 100.0% | 0 | 0 |
| 11.7.0 | 1 | 5.4 | 0.9% | 0 | 0 |
| 11.6.0 | 1 | 5.4 | 0.9% | 0 | 0 |
| 11.5.0 | 1 | 5.4 | 0.9% | 0 | 0 |
| 11.4.0 | 51 | 5.7 | 1.5% | 0 | 0 |
| 11.3.0 | 49 | 5.8 | 1.5% | 0 | 0 |