Communications Cloud Native Core Unified Data Repository
communications_cloud_native_core_unified_data_repository
Vendor: Oracle • 42 CVEs
CVEs (42)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Alibaba Oracle2Communications Cloud Native Core Unified Data Repository FastjsonNov 21, 2024 Jun 10, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 The package com.alibaba:fastjson before 1.2.83 are vulnerable to Deserialization of Untrusted Data by bypassing the default autoType shutdown restrictions, which is possible under certain conditions. Exploiting this vuln...Show more |
5Cisco OracleSiemens+2 more38Access Appliance Commerce PlatformCommunications Cloud Native Core Automated Test Suite+35 moreOct 30, 2025 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the a...Show more |
2Oracle Vmware28Banking Branch Banking Cash ManagementBanking Corporate Lending Process Management+25 moreOct 30, 2025 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in rem...Show more |
4Debian FasterxmlNetapp+1 more36Active Iq Unified Manager Big Data Spatial And GraphCloud Insights Acquisition Unit+33 moreAug 27, 2025 Mar 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreMay 5, 2025 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
3Debian GnuOracle8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreMay 5, 2025 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer o...Show more |
3Debian GnuOracle4Communications Cloud Native Core Unified Data Repository Debian LinuxEnterprise Operations Monitor+1 moreMay 5, 2025 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer ov...Show more |
5Apache DebianNetapp+2 more1166bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+113 moreMay 29, 2026 Dec 18, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data t...Show more |
5Debian NetappNetty+2 more18Banking Deposits And Lines Of Credit Servicing Banking Party ManagementBanking Platform+15 moreNov 21, 2024 Dec 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance protocol servers & clients. Netty prior to version 4.1.71.Final skips control chars when they are...Show more |
2Gnu Oracle7Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+4 moreNov 21, 2024 Nov 4, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This...Show more |
5Debian NetappNetty+2 more19Banking Apis Banking Digital ExperienceCoherence+16 moreNov 21, 2024 Oct 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The...Show more |
7Debian McafeeNetapp+4 more32Clustered Data Ontap Clustered Data Ontap Antivirus ConnectorCommunications Cloud Native Core Console+29 moreApr 16, 2026 Aug 24, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ASN.1 strings are represented internally within OpenSSL as an ASN1_STRING structure which contains a buffer holding the string data and a field holding the buffer length. This contrasts with normal C strings which are re...Show more |
5Debian NetappOpenssl+2 more31Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+28 moreNov 21, 2024 Aug 24, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In order to decrypt SM2 encrypted data an application is expected to call the API function EVP_PKEY_decrypt(). Typically an application will call this function twice. The first time, on entry, the "out" parameter can be...Show more |
3Fedoraproject GnuOracle8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreMay 30, 2025 Aug 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side...Show more |
3Eclipse NetappOracle18Autovue For Agile Product Lifecycle Management Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Security Edge Protection Proxy+15 moreNov 21, 2024 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a...Show more |
3Apache NetappOracle34Active Iq Unified Manager Banking ApisBanking Digital Experience+31 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted ZIP archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle27Active Iq Unified Manager Banking ApisBanking Digital Experience+24 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of serv...Show more |
3Apache NetappOracle24Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+21 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of servi...Show more |
3Apache NetappOracle26Active Iq Unified Manager Banking Digital ExperienceBanking Enterprise Default Management+23 moreNov 21, 2024 Jul 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When reading a specially crafted 7Z archive, the construction of the list of codecs that decompress an entry can result in an infinite loop. This could be used to mount a denial of service attack against services that us...Show more |
2Oracle Websockets Project5Communications Cloud Native Core Policy Communications Cloud Native Core Security Edge Protection ProxyCommunications Cloud Native Core Service Communication Proxy+2 moreNov 21, 2024 Jun 6, 2021 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The aaugustin websockets library before 9.1 for Python has an Observable Timing Discrepancy on servers when HTTP Basic Authentication is enabled with basic_auth_protocol_factory(credentials=...). An attacker may be able...Show more |