📦 Communications Cloud Native Core Service Communication Proxy

by Oracle

🔍 What is Communications Cloud Native Core Service Communication Proxy?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-22947

CRITICAL CVSS 10.0 Mar 3, 2022

CVE-2022-22947 is a critical remote code execution vulnerability in Spring Cloud Gateway when the Actuator endpoint is enabled and exposed without proper security controls. Attackers can send speciall...

CVE-2020-36518

HIGH CVSS 7.5 Mar 11, 2022

CVE-2020-36518 is a denial-of-service vulnerability in Jackson Databind where processing deeply nested JSON objects causes a Java StackOverflowError, crashing the application. This affects any Java ap...

CVE-2021-35515

HIGH CVSS 7.5 Jul 13, 2021

CVE-2021-35515 is a denial-of-service vulnerability in Apache Commons Compress's 7Z archive handling. When processing a specially crafted 7Z file, the codec list construction can enter an infinite loo...

CVE-2021-35517

HIGH CVSS 7.5 Jul 13, 2021

CVE-2021-35517 is a denial-of-service vulnerability in Apache Commons Compress where specially crafted TAR archives can trigger excessive memory allocation, leading to out-of-memory errors. This affec...

CVE-2021-22901

HIGH CVSS 8.1 Jun 11, 2021

CVE-2021-22901 is a use-after-free vulnerability in curl/libcurl that allows a malicious TLS 1.3 server to potentially execute arbitrary code on the client. This affects curl clients using OpenSSL wit...

CVE-2021-33560

HIGH CVSS 7.5 Jun 8, 2021

This vulnerability in Libgcrypt allows side-channel attacks against ElGamal encryption due to missing exponent blinding and inappropriate window size selection. Attackers can potentially recover priva...

CVE-2021-22118

HIGH CVSS 7.8 May 27, 2021

This vulnerability allows a locally authenticated malicious user to escalate privileges in Spring Framework WebFlux applications by manipulating temporary storage directories. Attackers can read or mo...

CVE-2020-29582

MEDIUM CVSS 5.3 Feb 3, 2021

This vulnerability in JetBrains Kotlin before version 1.4.21 uses an insecure Java API for temporary file creation, allowing attackers to read sensitive data from improperly secured temporary files an...