cbcvebase.

Oracle Communications Billing And Revenue Management vulnerabilities

66 known vulnerabilities affecting oracle/communications_billing_and_revenue_management.

Total CVEs
66
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH33MEDIUM11LOW5

Vulnerabilities

Page 4 of 4
CVE-2020-9488P4LOWCVSS 3.7v7.5.0.23.0v12.0.0.3.02020-04-27
CVE-2020-9488 [LOW] CWE-295 CVE-2020-9488: Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allo Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1
nvd
CVE-2020-8284P4LOWCVSS 3.7v12.0.0.3.02020-12-14
CVE-2020-8284 [LOW] CWE-200 CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting ba A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
nvd
CVE-2020-7016P4MEDIUMCVSS 4.8v12.0.0.3.02020-07-27
CVE-2020-7016 [MEDIUM] CWE-185 CVE-2020-7016: Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attac Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion. An attacker can construct a URL that when viewed by a Kibana user can lead to the Kibana process consuming large amounts of CPU and becoming unresponsive.
nvd
CVE-2021-22890P4LOWCVSS 3.7v12.0.0.3.02021-04-01
CVE-2021-22890 [LOW] CWE-300 CVE-2021-22890: curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MI curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the ho
nvd
CVE-2022-21267P4LOWCVSS 3.3v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21267 [LOW] CVE-2022-21267: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Ma
nvd
CVE-2022-21268P4LOWCVSS 3.3v12.0.0.3.0v12.0.0.4.02022-01-19
CVE-2022-21268 [LOW] CVE-2022-21268: Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communic Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Billing and Revenue Ma
nvd
Oracle Communications Billing And Revenue Management vulnerabilities | cvebase