Oracle Communications Billing And Revenue Management vulnerabilities

66 known vulnerabilities affecting oracle/communications_billing_and_revenue_management.

Total CVEs
66
CISA KEV
0
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL17HIGH33MEDIUM11LOW5

Vulnerabilities

Page 1 of 4
CVE-2022-21601MEDIUMCVSS 6.5≥ 12.0.0.4.0, ≤ 12.0.0.7.02022-10-18
CVE-2022-21601 [MEDIUM] CVE-2022-21601: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and R
nvd
CVE-2022-21429HIGHCVSS 8.1≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21429 [HIGH] CVE-2022-21429: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenu
nvd
CVE-2022-21574MEDIUMCVSS 5.3≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21574 [MEDIUM] CVE-2022-21574: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and
nvd
CVE-2022-21572MEDIUMCVSS 5.4≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21572 [MEDIUM] CVE-2022-21572: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue
nvd
CVE-2022-21573MEDIUMCVSS 6.5≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21573 [MEDIUM] CVE-2022-21573: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue
nvd
CVE-2022-21431CRITICALCVSS 10.0v12.0.0.4v12.0.0.52022-04-19
CVE-2022-21431 [CRITICAL] CVE-2022-21431: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and
nvd
CVE-2022-21430HIGHCVSS 8.5v12.0.0.4v12.0.0.52022-04-19
CVE-2022-21430 [HIGH] CVE-2022-21430: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Re
nvd
CVE-2022-21422HIGHCVSS 7.5v12.0.0.4v12.0.0.52022-04-19
CVE-2022-21422 [HIGH] CVE-2022-21422: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Re
nvd
CVE-2022-21424HIGHCVSS 8.3v12.0.0.42022-04-19
CVE-2022-21424 [HIGH] CVE-2022-21424: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Manageme
nvd
CVE-2020-36518HIGHCVSS 7.5≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2022-21390CRITICALCVSS 10.0v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21390 [CRITICAL] CVE-2022-21390: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Webservices Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing a
nvd
CVE-2022-21276CRITICALCVSS 9.9v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21276 [CRITICAL] CVE-2022-21276: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and
nvd
CVE-2022-21275CRITICALCVSS 10.0v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21275 [CRITICAL] CVE-2022-21275: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing an
nvd
CVE-2022-21391CRITICALCVSS 9.9v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21391 [CRITICAL] CVE-2022-21391: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and
nvd
CVE-2022-21389CRITICALCVSS 10.0v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21389 [CRITICAL] CVE-2022-21389: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing an
nvd
CVE-2022-21266HIGHCVSS 7.5v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21266 [HIGH] CVE-2022-21266: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Reve
nvd
CVE-2022-21267LOWCVSS 3.3v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21267 [LOW] CVE-2022-21267: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Ma
nvd
CVE-2022-21268LOWCVSS 3.3v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21268 [LOW] CVE-2022-21268: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Ma
nvd
CVE-2021-45105MEDIUMCVSS 5.9v12.0.0.4v12.0.0.52021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2021-2351HIGHCVSS 7.5v12.0.0.4v12.0.0.52021-07-21
CVE-2021-2351 [HIGH] CWE-327 CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versi Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a perso
nvd