Skip to main content

Vendor/product archive

oracle / communications_cloud_native_core_console CVEs

Beta · best-effort

19 CVEs tagged to oracle / communications_cloud_native_core_console4 Critical, 6 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2022-22963

Published Apr 1, 2022

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a…

CVSS 9.8 · Critical
evidence mentions
17
Buzz score
77.3
KEV listedPublic PoC observed

CVE-2022-22946

Published Mar 4, 2022

In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an i…

CVSS 5.5 · Medium

CVE-2021-22569

Published Jan 10, 2022

An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can…

CVSS 7.5 · High

CVE-2021-41973

Published Nov 1, 2021

In Apache MINA, a specifically crafted, malformed HTTP request may cause the HTTP Header decoder to loop indefinitely. The decoder assumed that the HTTP Header begins at the begin…

CVSS 6.5 · Medium

CVE-2021-22096

Published Oct 28, 2021

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additio…

CVSS 4.3 · Medium

CVE-2021-2471

Published Oct 20, 2021

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerabili…

CVSS 5.9 · Medium

CVE-2021-30129

Published Jul 12, 2021

A vulnerability in sshd-core of Apache Mina SSHD allows an attacker to overflow the server causing an OutOfMemory error. This issue affects the SFTP and port forwarding features o…

CVSS 6.5 · Medium
Showing 1-19 of 19 CVEsPage 1 of 1