VendorsOraclecommunications_policy_managementall versions
Vulnerabilities

Oracle Communications Policy Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

50CVEs
CVE-2015-0235
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
Published 2015-01-28 · Modified
10.02 PoCEPSS 0.946
CVE-2021-21345
XStream is vulnerable to a Remote Command Execution attack
Published 2021-03-22 · Analyzed
9.9EPSS 0.723
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Published 2022-04-01 · Analyzed
9.8KEVEPSS 0.996
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
Published 2020-09-14 · Modified
9.81 PoCEPSS 0.974
CVE-2020-17530
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Published 2020-12-11 · Analyzed
9.8KEVEPSS 0.959
CVE-2021-21346
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.764
CVE-2021-21344
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.760
CVE-2021-23450
Prototype Pollution
Published 2021-12-17 · Modified
9.8EPSS 0.304
CVE-2021-43527
NSS (Network Security Services) versions prior to 3.73 or 3.68.1 ESR are vulnerable to a heap overflow when handling DER-encoded DSA or RSA-PSS signatures. Applications using NSS for handling signatures encoded within CMS, S/MIME, PKCS \#7, or PKCS \#12 are likely to be impacted. Applications using NSS for certificate validation or other TLS, X.509, OCSP or CRL functionality may be impacted, depending on how they configure NSS. *Note: This vulnerability does NOT impact Mozilla Firefox.* However, email clients and PDF viewers that use NSS for signature verification, such as Thunderbird, LibreOffice, Evolution and Evince are believed to be impacted. This vulnerability affects NSS < 3.73 and NSS < 3.68.1.
Published 2021-12-08 · Modified
9.8EPSS 0.176
CVE-2021-21350
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.152
CVE-2021-21347
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.8EPSS 0.143
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag which doesn't have value and action set and in same time, its upper package have no or wildcard namespace.
Published 2018-08-22 · Analyzed
9.3KEV3 PoCEPSS 1.000
CVE-2020-26217
Remote Code Execution in XStream
Published 2020-11-16 · Analyzed
9.3EPSS 0.850
CVE-2021-21351
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-03-22 · Analyzed
9.1EPSS 0.821
CVE-2021-21342
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
9.1EPSS 0.500
CVE-2020-36179
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.171
CVE-2020-36184
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.
Published 2021-01-06 · Modified
8.8EPSS 0.084
CVE-2020-36180
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.040
CVE-2020-36181
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.040
CVE-2020-36182
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
Published 2021-01-06 · Modified
8.8EPSS 0.040
CVE-2021-21349
A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host
Published 2021-03-22 · Analyzed
8.6EPSS 0.468
CVE-2020-35728
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).
Published 2020-12-27 · Analyzed
8.1EPSS 0.125
CVE-2020-36188
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource.
Published 2021-01-06 · Modified
8.1EPSS 0.088
CVE-2020-24616
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).
Published 2020-08-25 · Modified
8.1EPSS 0.076
CVE-2020-24750
FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
Published 2020-09-17 · Modified
8.1EPSS 0.073
CVE-2020-36183
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.
Published 2021-01-06 · Analyzed
8.1EPSS 0.049
CVE-2020-36185
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource.
Published 2021-01-06 · Modified
8.1EPSS 0.042
CVE-2020-36186
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource.
Published 2021-01-06 · Modified
8.1EPSS 0.042
CVE-2020-36187
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
Published 2021-01-06 · Modified
8.1EPSS 0.042
CVE-2020-5398
RFD Attack via "Content-Disposition" Header Sourced from Request Input by Spring MVC or Spring WebFlux Application
Published 2020-01-16 · Modified
8.0EPSS 0.888
CVE-2021-21348
XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos)
Published 2021-03-22 · Analyzed
7.8EPSS 0.138
CVE-2020-5258
Prototype pollution in dojo
Published 2020-03-10 · Modified
7.7EPSS 0.040
CVE-2019-0233
An access permission override in Apache Struts 2.0.0 to 2.5.20 may cause a Denial of Service when performing a file upload.
Published 2020-09-14 · Modified
7.5EPSS 0.681
CVE-2021-21343
XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights
Published 2021-03-22 · Analyzed
7.5EPSS 0.467
CVE-2015-0411
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
Published 2015-01-21 · Modified
7.5EPSS 0.096
CVE-2021-43859
Denial of Service by injecting highly recursive collections or maps in XStream
Published 2022-02-01 · Modified
7.5EPSS 0.079
CVE-2017-3633
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached). Supported versions that are affected are 5.6.36 and earlier and 5.7.18 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Memcached to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 6.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H).
Published 2017-08-08 · Modified
6.5EPSS 0.030
CVE-2017-10159
Vulnerability in the Oracle Communications Policy Management component of Oracle Communications Applications (subcomponent: Portal, CMP). Supported versions that are affected are 11.5 and 12.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Policy Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Policy Management accessible data as well as unauthorized read access to a subset of Oracle Communications Policy Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Published 2017-10-19 · Modified
6.1EPSS 0.014
CVE-2018-1271
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Published 2018-04-06 · Modified
5.9EPSS 0.344
CVE-2021-29425
Possible limited path traversal vulnerabily in Apache Commons IO
Published 2021-04-13 · Modified
5.8EPSS 0.099
1 / 2Next →