Skip to main content

Vendor/product archive

oracle / communications_session_route_manager CVEs

Beta · best-effort

59 CVEs tagged to oracle / communications_session_route_manager6 Critical, 35 High, 16 Medium, 2 Low, 0 Unrated.

CVE-2021-44790

Published Dec 20, 2021

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an expl…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2021-44224

Published Dec 20, 2021

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy d…

CVSS 8.2 · High
evidence mentions
2
Buzz score
17.5

CVE-2021-22696

Published Apr 2, 2021

CXF supports (via JwtRequestCodeFilter) passing OAuth 2 parameters via a JWT token as opposed to query parameters (see: The OAuth 2.0 Authorization Framework: JWT Secured Authoriz…

CVSS 7.5 · High

CVE-2021-26117

Published Jan 27, 2021

The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache…

CVSS 7.5 · High

CVE-2020-11998

Published Sep 10, 2020

A regression has been introduced in the commit preventing JMX re-bind. By passing an empty environment map to RMIConnectorServer, instead of the map that contains the authenticati…

CVSS 9.8 · Critical

CVE-2020-11993

Published Aug 7, 2020

Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong con…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 59 CVEsPage 1 of 3