📦 Communications Cloud Native Core Console

by Oracle

🔍 What is Communications Cloud Native Core Console?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-22963

CRITICAL CVSS 9.8 Apr 1, 2022

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Spring Cloud Function. Attackers can craft malicious SpEL expressions in routing function...

CVE-2022-22947

CRITICAL CVSS 10.0 Mar 3, 2022

CVE-2022-22947 is a critical remote code execution vulnerability in Spring Cloud Gateway when the Actuator endpoint is enabled and exposed without proper security controls. Attackers can send speciall...

CVE-2022-23221

CRITICAL CVSS 9.8 Jan 19, 2022

This vulnerability allows remote attackers to execute arbitrary code on H2 Database Console by exploiting a flaw in JDBC URL parsing. Attackers can craft malicious URLs containing INIT=RUNSCRIPT comma...

CVE-2020-36518

HIGH CVSS 7.5 Mar 11, 2022

CVE-2020-36518 is a denial-of-service vulnerability in Jackson Databind where processing deeply nested JSON objects causes a Java StackOverflowError, crashing the application. This affects any Java ap...

CVE-2022-24407

HIGH CVSS 8.8 Feb 24, 2022

CVE-2022-24407 is a SQL injection vulnerability in Cyrus SASL authentication library. It allows attackers to inject arbitrary SQL commands via unescaped passwords in SQL INSERT/UPDATE statements. Syst...

CVE-2021-22569

HIGH CVSS 7.5 Jan 10, 2022

This vulnerability in protobuf-java allows attackers to craft malicious Protocol Buffer messages that cause excessive CPU consumption through parser inefficiencies. It affects any Java application usi...

CVE-2021-3712

HIGH CVSS 7.4 Aug 24, 2021

This OpenSSL vulnerability allows attackers to cause buffer overruns when applications directly construct ASN.1 strings without proper NUL termination. Exploitation can lead to denial of service or me...