Communications Cloud Native Core Security Edge Protection Proxy
communications_cloud_native_core_security_edge_protection_proxy
Vendor: Oracle • 26 CVEs
CVEs (26)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Cisco OracleSiemens+2 more38Access Appliance Commerce PlatformCommunications Cloud Native Core Automated Test Suite+35 moreOct 30, 2025 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the a...Show more |
2Oracle Vmware28Banking Branch Banking Cash ManagementBanking Corporate Lending Process Management+25 moreOct 30, 2025 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in rem...Show more |
4Debian FasterxmlNetapp+1 more36Active Iq Unified Manager Big Data Spatial And GraphCloud Insights Acquisition Unit+33 moreAug 27, 2025 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
2Oracle Vmware6Commerce Guided Search Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Console+3 moreNov 21, 2024 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gate...Show more |
2Oracle Vmware10Commerce Guided Search Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Console+7 moreOct 30, 2025 Mar 3, 2022 N/A· v4 10.0 CRITICAL· v3 6.8 MEDIUM· v2 In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a ma...Show more |
5Cyrusimap DebianFedoraproject+2 more8Active Iq Unified Manager Communications Cloud Native Core ConsoleCommunications Cloud Native Core Network Function Cloud Native Environment+5 moreNov 21, 2024 Feb 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement. |
3Debian GnuOracle8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreMay 5, 2025 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer o...Show more |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreMay 29, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |
5Debian NetappNetty+2 more18Banking Deposits And Lines Of Credit Servicing Banking Party ManagementBanking Platform+15 moreNov 21, 2024 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are...Show more |
2Gnu Oracle7Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+4 moreNov 21, 2024 Nov 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This...Show more |
2Oracle Quarkus6Communications Cloud Native Core Console Communications Cloud Native Core Network Slice Selection FunctionCommunications Cloud Native Core Policy+3 moreNov 21, 2024 Oct 20, 2021 N/A· v4 5.9 MEDIUM· v3 7.9 HIGH· v2 Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with n...Show more |
5Debian NetappNetty+2 more19Banking Apis Banking Digital ExperienceCoherence+16 moreNov 21, 2024 Oct 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The...Show more |
8Apple DebianFedoraproject+5 more26Cloud Backup Clustered Data OntapCommerce Guided Search+23 moreApr 16, 2026 Sep 29, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl woul...Show more |
8Apple DebianFedoraproject+5 more29Cloud Backup Clustered Data OntapCommerce Guided Search+26 moreApr 16, 2026 Sep 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A user can tell curl >= 7.20.0 and <= 7.78.0 to require a successful upgrade to TLS when speaking to an IMAP, POP3 or FTP server (`--ssl-reqd` on the command line or`CURLOPT_USE_SSL` set to `CURLUSESSL_CONTROL` or `CURLU...Show more |
7Debian McafeeNetapp+4 more32Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorCommunications Cloud Native Core Console+29 moreApr 16, 2026 Aug 24, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are re...Show more |
5Debian NetappOpenssl+2 more31Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+28 moreNov 21, 2024 Aug 24, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be...Show more |
3Fedoraproject GnuOracle8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreMay 30, 2025 Aug 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side...Show more |
3Eclipse NetappOracle18Autovue For Agile Product Lifecycle Management Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Security Edge Protection Proxy+15 moreNov 21, 2024 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a...Show more |
2Oracle Websockets Project5Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection ProxyCommunications Cloud Native Core Service Communication Proxy+2 moreNov 21, 2024 Jun 6, 2021 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able...Show more |
2Oracle Redhat14Communications Cloud Native Core Console Communications Cloud Native Core Network Repository FunctionCommunications Cloud Native Core Policy+11 moreNov 21, 2024 Jun 2, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affec...Show more |