CVEs (75)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectJenkins+2 more11Commerce Guided Search Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 moreJun 17, 2026 Feb 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more |
5Apache CiscoDebian+2 more22Cloudcenter Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+19 moreJun 17, 2026 Dec 28, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so...Show more |
3Apache DebianOracle18Agile Plm Commerce Guided SearchCommerce Platform+15 moreJun 17, 2026 Sep 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference e...Show more |
1Oracle 111Advanced Networking Option Agile Engineering Data ManagementAgile Plm+108 moreJun 17, 2026 Jul 21, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker...Show more |
4Apache DebianNetapp+1 more9Activemq Activemq ArtemisArtemis+6 moreJun 17, 2026 Jan 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache ActiveMQ prior to versions 5.16.1 and 5.1...Show more |
5Apache DebianEclipse+2 more17Blockchain Platform Communications Converged Application Server Service ControllerCommunications Offline Mediation Controller+14 moreJun 17, 2026 Nov 28, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto...Show more |
5Apache DebianEclipse+2 more18Beam Communications Application Session ControllerCommunications Converged Application Server Service Controller+15 moreJun 17, 2026 Oct 23, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that syste...Show more |
4Apache FedoraprojectGradle+1 more37Agile Engineering Data Management AntApi Gateway+34 moreJun 17, 2026 Oct 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file...Show more |
3Netapp OracleVmware38Commerce Guided Search Communications BrmCommunications Design Studio+35 moreJun 17, 2026 Sep 19, 2020 N/A· v4 6.5 MEDIUM· v3 3.6 LOW· v2 In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser...Show more |
3Apache DebianOracle4Activemq Communications Diameter Signaling RouterDebian Linux+1 moreJun 17, 2026 Sep 10, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Apache ActiveMQ uses LocateRegistry.createRegistry() to create the JMX RMI registry and binds the server to the "jmxrmi" entry. It is possible to connect to the registry without authentication and call the rebind method...Show more |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 Sep 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authentication credentials, it leaves ActiveMQ open t...Show more |
2Oracle Vmware8Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+5 moreJun 17, 2026 Jul 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to...Show more |
2Apache Oracle7Activemq Communications Diameter Signaling RouterCommunications Element Manager+4 moreJun 17, 2026 May 14, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a queue. |
2Apache Oracle4Camel Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 moreJun 17, 2026 May 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
2Apache Oracle4Camel Communications Diameter Signaling RouterEnterprise Manager Base Platform+1 moreJun 17, 2026 May 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache Camel RabbitMQ enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1.0 are affected. 2.x users should upgrade to 2.25.1, 3.x users should upgrade to 3.2.0. |
2Apache Oracle5Camel Communications Diameter Intelligence HubCommunications Diameter Signaling Router+2 moreJun 17, 2026 May 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Camel's JMX is vulnerable to Rebind Flaw. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.x, 3.0.0 up to 3.1.0 is affected. Users should upgrade to 3.2.0. |
5Apache CanonicalFedoraproject+2 more50Agile Engineering Data Management AntBanking Enterprise Collections+47 moreJun 17, 2026 May 14, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more |
4Apache DebianOracle+1 more46Communications Application Session Controller Communications Billing And Revenue ManagementCommunications Eagle Ftp Table Base Retrieval+43 moreJun 17, 2026 Apr 27, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through tha...Show more |
2Apache Oracle5Communications Messaging Server Flexcube Private BankingPrimavera Unifier+2 moreJun 17, 2026 Apr 27, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt file may trigger a System.exit in Tika's OneNote Parser. Crafted or corrupted files can also cause out of memory errors and/or infinite loops in Tika's ICNSParser, MP3Parser, MP4Parser, SAS...Show more |
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. |