VendorsOraclecommunications_cloud_native_core_policy1.15.0
Vulnerabilities

Oracle Communications Cloud Native Core Policy 1.15.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2021-42392
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
Published 2022-01-07 · Modified
10.0EPSS 0.832
CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Published 2022-04-01 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Published 2022-04-01 · Analyzed
9.8KEVEPSS 0.996
CVE-2021-2471
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
Published 2021-10-20 · Modified
7.9EPSS 0.075
CVE-2021-3807
Inefficient Regular Expression Complexity in chalk/ansi-regex
Published 2021-09-17 · Modified
7.8EPSS 0.036
CVE-2021-23840
Integer overflow in CipherUpdate
Published 2021-02-16 · Modified
7.5EPSS 0.507
CVE-2021-37136
The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Decoder are affected. The malicious input can trigger an OOME and so a DoS attack
Published 2021-10-19 · Modified
7.5EPSS 0.059
CVE-2019-20916
The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/authorized_keys file. This occurs in _download_http_url in _internal/download.py.
Published 2020-09-04 · Modified
7.5EPSS 0.030
CVE-2021-35574
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Filters). The supported version that is affected is 8.5.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology. Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS Base Score depend on the software that uses Outside In Technology. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Published 2021-10-20 · Modified
7.5EPSS 0.020
CVE-2021-22569
Denial of Service of protobuf-java parsing procedure
Published 2022-01-07 · Modified
7.5EPSS 0.017
CVE-2022-23181
Local privilege escalation with FileStore
Published 2022-01-27 · Modified
7.0EPSS 0.007
CVE-2019-3799
Directory Traversal with spring-cloud-config-server
Published 2019-05-06 · Modified
6.51 PoCEPSS 0.853
CVE-2021-43797
HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling
Published 2021-12-09 · Modified
6.5EPSS 0.027
CVE-2020-8554
Kubernetes man in the middle using LoadBalancer or ExternalIPs
Published 2021-01-21 · Modified
6.3EPSS 0.093
CVE-2021-28168
Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the contents of this file are viewable by all other users locally on the system. As such, if the contents written is security sensitive, it can be disclosed to other local users.
Published 2021-04-22 · Modified
6.2EPSS 0.009
CVE-2021-45105
Apache Log4j2 does not always protect from infinite recursion in lookup evaluation
Published 2021-12-18 · Modified
5.9EPSS 1.000
CVE-2021-23841
Null pointer deref in X509_issuer_and_serial_hash()
Published 2021-02-16 · Modified
5.9EPSS 0.074
CVE-2021-38153
Timing Attack Vulnerability for Apache Kafka Connect and Clients
Published 2021-09-22 · Modified
5.9EPSS 0.063
CVE-2020-16135
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
Published 2020-07-29 · Modified
5.9EPSS 0.041
CVE-2021-3572
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Published 2021-11-10 · Modified
5.7EPSS 0.018
CVE-2020-14155
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
Published 2020-06-15 · Modified
5.3EPSS 0.042
CVE-2021-3200
Buffer overflow vulnerability in libsolv 2020-12-13 via the Solver * testcase_read(Pool *pool, FILE *fp, const char *testcase, Queue *job, char **resultp, int *resultflagsp function at src/testcase.c: line 2334, which could cause a denial of service
Published 2021-05-18 · Modified
4.3EPSS 0.013