VendorsOraclecommunications_cloud_native_core_policy22.1.3
Vulnerabilities

Oracle Communications Cloud Native Core Policy 22.1.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Published 2022-04-01 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2021-3572
A flaw was found in python-pip in the way it handled Unicode separators in git references. A remote attacker could possibly use this issue to install a different revision on a repository. The highest threat from this vulnerability is to data integrity. This is fixed in python-pip version 21.1.
Published 2021-11-10 · Modified
5.7EPSS 0.018
CVE-2021-34141
An incomplete string comparison in the numpy.core component in NumPy before 1.22.0 allows attackers to trigger slightly incorrect copying by constructing specific string objects. NOTE: the vendor states that this reported code behavior is "completely harmless."
Published 2021-12-17 · Modified
5.3EPSS 0.016