📦 Communications Cloud Native Core Network Exposure Function

by Oracle

🔍 What is Communications Cloud Native Core Network Exposure Function?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-22963

CRITICAL CVSS 9.8 Apr 1, 2022

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Spring Cloud Function. Attackers can craft malicious SpEL expressions in routing function...

CVE-2022-22947

CRITICAL CVSS 10.0 Mar 3, 2022

CVE-2022-22947 is a critical remote code execution vulnerability in Spring Cloud Gateway when the Actuator endpoint is enabled and exposed without proper security controls. Attackers can send speciall...

CVE-2021-3773

CRITICAL CVSS 9.8 Feb 16, 2022

A netfilter flaw allows network-connected attackers to infer OpenVPN connection endpoint information by analyzing network traffic patterns. This affects Linux systems running OpenVPN with netfilter en...

CVE-2022-1154

HIGH CVSS 7.8 Mar 30, 2022

CVE-2022-1154 is a use-after-free vulnerability in Vim's utf_ptr2char function that could allow an attacker to execute arbitrary code or cause a denial of service. Users who open specially crafted fil...

CVE-2022-25636

HIGH CVSS 7.8 Feb 24, 2022

CVE-2022-25636 is a heap out-of-bounds write vulnerability in the Linux kernel's netfilter component that allows local users to escalate privileges to root. The vulnerability affects Linux kernel vers...

CVE-2021-20322

HIGH CVSS 7.4 Feb 18, 2022

This Linux kernel vulnerability allows remote attackers to bypass UDP source port randomization by exploiting flaws in ICMP error processing. Attackers can scan open UDP ports more effectively, compro...

CVE-2021-3752

HIGH CVSS 7.1 Feb 16, 2022

A use-after-free vulnerability in the Linux kernel's Bluetooth subsystem allows local attackers to crash the system or potentially escalate privileges through a race condition when connecting and disc...

CVE-2021-4083

HIGH CVSS 7.0 Jan 18, 2022

A race condition vulnerability in the Linux kernel's Unix domain socket garbage collection allows local users to trigger a read-after-free memory flaw. This can lead to system crashes or privilege esc...

CVE-2021-3612

HIGH CVSS 7.8 Jul 9, 2021

A local privilege escalation vulnerability in Linux kernel versions before 5.9-rc1 allows attackers with local access to crash systems or gain root privileges through improper bounds checking in joyst...