Communications Cloud Native Core Console
communications_cloud_native_core_console
Vendor: Oracle • 23 CVEs
CVEs (23)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Cisco OracleSiemens+2 more38Access Appliance Commerce PlatformCommunications Cloud Native Core Automated Test Suite+35 moreOct 30, 2025 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the a...Show more |
2Oracle Vmware28Banking Branch Banking Cash ManagementBanking Corporate Lending Process Management+25 moreOct 30, 2025 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in rem...Show more |
4Debian FasterxmlNetapp+1 more36Active Iq Unified Manager Big Data Spatial And GraphCloud Insights Acquisition Unit+33 moreAug 27, 2025 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
2Oracle Vmware6Commerce Guided Search Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Console+3 moreNov 21, 2024 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gate...Show more |
2Oracle Vmware10Commerce Guided Search Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Console+7 moreOct 30, 2025 Mar 3, 2022 N/A· v4 10.0 CRITICAL· v3 6.8 MEDIUM· v2 In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a ma...Show more |
5Cyrusimap DebianFedoraproject+2 more8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Network Function Cloud Native Environment+5 moreNov 21, 2024 Feb 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. |
3Debian H2databaseOracle3Communications Cloud Native Core Console Debian LinuxH2May 5, 2025 Jan 19, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability...Show more |
2Google Oracle7Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+4 moreNov 21, 2024 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by...Show more |
2Oracle Vmware3Communications Cloud Native Core Console Communications Cloud Native Core Service Communication ProxySpring FrameworkNov 21, 2024 Jan 10, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to C...Show more |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreMay 29, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |
2Apache Oracle9Banking Payments Banking Trade Finance Process ManagementBanking Treasury Management+6 moreNov 21, 2024 Nov 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the beginning of the buffer and loops if there is...Show more |
3Netapp OracleVmware8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Service Communication Proxy+5 moreNov 21, 2024 Oct 28, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. |
2Oracle Quarkus6Communications Cloud Native Core Console Communications Cloud Native Core Network Slice Selection FunctionCommunications Cloud Native Core Policy+3 moreNov 21, 2024 Oct 20, 2021 N/A· v4 5.9 MEDIUM· v3 7.9 HIGH· v2 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with n...Show more |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreApr 16, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreApr 16, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
7Debian McafeeNetapp+4 more32Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorCommunications Cloud Native Core Console+29 moreApr 16, 2026 Aug 24, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are re...Show more |
2Apache Oracle9Banking Payments Banking Trade FinanceBanking Treasury Management+6 moreNov 21, 2024 Jul 12, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features of Apache Mina SSHD version 2.0.0 and late...Show more |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreNov 21, 2024 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |
5Debian NetappNetty+2 more18Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Trade Finance Process Management+15 moreNov 21, 2024 Mar 30, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Netty is an open-source, asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. In Netty (io.netty:netty-codec-http2) before version 4.1...Show more |
4Netapp OracleQuarkus+1 more4Communications Cloud Native Core Console Oncommand InsightQuarkus+1 moreNov 21, 2024 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or q...Show more |