📦 Communications Cloud Native Core Network Slice Selection Function

by Oracle

🔍 What is Communications Cloud Native Core Network Slice Selection Function?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-22963

CRITICAL CVSS 9.8 Apr 1, 2022

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of Spring Cloud Function. Attackers can craft malicious SpEL expressions in routing function...

CVE-2022-22947

CRITICAL CVSS 10.0 Mar 3, 2022

CVE-2022-22947 is a critical remote code execution vulnerability in Spring Cloud Gateway when the Actuator endpoint is enabled and exposed without proper security controls. Attackers can send speciall...

CVE-2021-43527

CRITICAL CVSS 9.8 Dec 8, 2021

CVE-2021-43527 is a critical heap overflow vulnerability in NSS (Network Security Services) that allows remote code execution when processing malicious DER-encoded DSA or RSA-PSS signatures. It affect...

CVE-2021-29921

CRITICAL CVSS 9.8 May 6, 2021

The Python ipaddress library incorrectly interprets IP addresses with leading zeros in octets, treating them as octal numbers instead of decimal. This allows attackers to bypass IP-based access contro...

CVE-2020-36518

HIGH CVSS 7.5 Mar 11, 2022

CVE-2020-36518 is a denial-of-service vulnerability in Jackson Databind where processing deeply nested JSON objects causes a Java StackOverflowError, crashing the application. This affects any Java ap...

CVE-2022-23308

HIGH CVSS 7.5 Feb 26, 2022

CVE-2022-23308 is a use-after-free vulnerability in libxml2's validation component that allows attackers to potentially execute arbitrary code or cause denial of service. It affects applications that ...

CVE-2021-37136

HIGH CVSS 7.5 Oct 19, 2021

CVE-2021-37136 is a denial-of-service vulnerability in Netty's Bzip2Decoder that allows attackers to trigger out-of-memory errors by sending specially crafted Bzip2 compressed data. The vulnerability ...

CVE-2021-22901

HIGH CVSS 8.1 Jun 11, 2021

CVE-2021-22901 is a use-after-free vulnerability in curl/libcurl that allows a malicious TLS 1.3 server to potentially execute arbitrary code on the client. This affects curl clients using OpenSSL wit...

CVE-2021-33560

HIGH CVSS 7.5 Jun 8, 2021

This vulnerability in Libgcrypt allows side-channel attacks against ElGamal encryption due to missing exponent blinding and inappropriate window size selection. Attackers can potentially recover priva...

CVE-2020-29582

MEDIUM CVSS 5.3 Feb 3, 2021

This vulnerability in JetBrains Kotlin before version 1.4.21 uses an insecure Java API for temporary file creation, allowing attackers to read sensitive data from improperly secured temporary files an...

CVE-2020-8908

LOW CVSS 3.3 Dec 10, 2020

This vulnerability in Google Guava's createTempDir() method creates temporary directories with world-readable permissions on Unix-like systems, allowing any user on the same machine to potentially rea...