It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:oracle:application_express:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "21.1.0"
}
],
"source": "CPE_RANGE",
"vendor_product": "oracle:application_express"
},
{
"cpes": [
"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "8.0.6"
},
{
"last_affected": "8.0.9"
}
],
"source": "CPE_RANGE",
"vendor_product": "oracle:financial_services_analytical_applications_infrastructure"
},
{
"cpes": [
"cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "9.2.6.0"
}
],
"source": "CPE_RANGE",
"vendor_product": "oracle:jd_edwards_enterpriseone_tools"
},
{
"cpes": [
"cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "21.9"
}
],
"source": "CPE_RANGE",
"vendor_product": "oracle:siebel_ui_framework"
},
{
"cpes": [
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.5:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "9.3.5"
},
{
"last_affected": "9.3.5"
},
{
"introduced": "9.3.6"
},
{
"last_affected": "9.3.6"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:agile_product_lifecycle_management"
},
{
"cpes": [
"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "8.1.0"
},
{
"last_affected": "8.1.0"
},
{
"introduced": "8.1.1"
},
{
"last_affected": "8.1.1"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:financial_services_analytical_applications_infrastructure"
},
{
"cpes": [
"cpe:2.3:a:oracle:webcenter_sites:12.2.1.3.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "12.2.1.3.0"
},
{
"last_affected": "12.2.1.3.0"
},
{
"introduced": "12.2.1.4.0"
},
{
"last_affected": "12.2.1.4.0"
}
],
"source": "CPE_STRING",
"vendor_product": "oracle:webcenter_sites"
}
]
}