Skip to main content

Vendor/product archive

oracle / communications_element_manager CVEs

Beta · best-effort

66 CVEs tagged to oracle / communications_element_manager7 Critical, 44 High, 13 Medium, 2 Low, 0 Unrated.

CVE-2021-44790

Published Dec 20, 2021

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an expl…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-44224

Published Dec 20, 2021

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy d…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2021-22696

Published Apr 2, 2021

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authoriz…

CVSS 7.5 · High

CVE-2021-22112

Published Feb 23, 2021

Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is chan…

CVSS 8.8 · High

CVE-2021-26117

Published Jan 27, 2021

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache…

CVSS 7.5 · High
Showing 1-25 of 66 CVEsPage 1 of 3