Oracle Communications Billing And Revenue Management vulnerabilities
66 known vulnerabilities affecting oracle/communications_billing_and_revenue_management.
Total CVEs
66
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH33MEDIUM11LOW5
Vulnerabilities
Page 3 of 4
CVE-2020-36187P3HIGHCVSS 8.1v7.5.0.23.0v12.0.0.3.02021-01-06
CVE-2020-36187 [HIGH] CWE-502 CVE-2020-36187: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.
nvd
CVE-2020-36180P3HIGHCVSS 8.1v7.5.0.23.0v12.0.0.3.02021-01-07
CVE-2020-36180 [HIGH] CWE-502 CVE-2020-36180: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36182P3HIGHCVSS 8.1v7.5.0.23.0v12.0.0.3.02021-01-07
CVE-2020-36182 [HIGH] CWE-502 CVE-2020-36182: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36181P3HIGHCVSS 8.1v7.5.0.23.0v12.0.0.3.02021-01-06
CVE-2020-36181 [HIGH] CWE-502 CVE-2020-36181: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS.
nvd
CVE-2020-36189P3HIGHCVSS 8.1v7.5.0.23.0v12.0.0.3.02021-01-06
CVE-2020-36189 [HIGH] CWE-502 CVE-2020-36189: FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadg
FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.
nvd
CVE-2021-35516P3HIGHCVSS 7.5v12.0.0.42021-07-13
CVE-2021-35516 [HIGH] CWE-130 CVE-2021-35516: When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memor
When reading a specially crafted 7Z archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' sevenz package.
nvd
CVE-2022-21422P3HIGHCVSS 7.5v12.0.0.4v12.0.0.52022-04-19
CVE-2022-21422 [HIGH] CVE-2022-21422: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Re
nvd
CVE-2021-35517P3HIGHCVSS 7.5v12.0.0.42021-07-13
CVE-2021-35517 [HIGH] CWE-130 CVE-2021-35517: When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memo
When reading a specially crafted TAR archive, Compress can be made to allocate large amounts of memory that finally leads to an out of memory error even for very small inputs. This could be used to mount a denial of service attack against services that use Compress' tar package.
nvd
CVE-2020-8203P3HIGHCVSS 7.4v7.5.0.23.0v12.0.0.3.02020-07-15
CVE-2020-8203 [HIGH] CWE-770 CVE-2020-8203: Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
nvd
CVE-2020-12723P3HIGHCVSS 7.5v12.0.0.2.0v12.0.0.3.02020-06-05
CVE-2020-12723 [HIGH] CWE-120 CVE-2020-12723: regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
nvd
CVE-2020-8286P3HIGHCVSS 7.5v12.0.0.3.02020-12-14
CVE-2020-8286 [HIGH] CWE-295 CVE-2020-8286: curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insu
curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.
nvd
CVE-2020-36518P3HIGHCVSS 7.5≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-03-11
CVE-2020-36518 [HIGH] CWE-787 CVE-2020-36518: jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a lar
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
nvd
CVE-2021-3345P3HIGHCVSS 7.8v12.0.0.3.02021-01-29
CVE-2021-3345 [HIGH] CWE-787 CVE-2021-3345: _gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer over
_gcry_md_block_write in cipher/hash-common.c in Libgcrypt version 1.9.0 has a heap-based buffer overflow when the digest final function sets a large count value. It is recommended to upgrade to 1.9.1 or later.
nvd
CVE-2022-21601P3MEDIUMCVSS 6.5≥ 12.0.0.4.0, ≤ 12.0.0.7.02022-10-18
CVE-2022-21601 [MEDIUM] CVE-2022-21601: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and R
nvd
CVE-2022-21573P4MEDIUMCVSS 6.5≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21573 [MEDIUM] CVE-2022-21573: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue
nvd
CVE-2021-22876P4MEDIUMCVSS 5.3v12.0.0.3.02021-04-01
CVE-2021-22876 [MEDIUM] CWE-359 CVE-2021-22876: curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP requests, and therefore risks leak
nvd
CVE-2020-7017P4MEDIUMCVSS 6.7v12.0.0.3.02020-07-27
CVE-2020-7017 [MEDIUM] CWE-79 CVE-2020-7017: In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS fla
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw. An attacker who is able to edit or create a region map visualization could obtain sensitive information or perform destructive actions on behalf of Kibana users who view the region map visualization.
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v12.0.0.3v12.0.0.42019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2022-21574P4MEDIUMCVSS 5.3≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21574 [MEDIUM] CVE-2022-21574: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and
nvd
CVE-2022-21572P4MEDIUMCVSS 5.4≥ 12.0.0.4.0, ≤ 12.0.0.6.02022-07-19
CVE-2022-21572 [MEDIUM] CVE-2022-21572: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic
Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Care). Supported versions that are affected are 12.0.0.4.0-12.0.0.6.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue
nvd