cbcvebase.

Oracle Communications Operations Monitor vulnerabilities

45 known vulnerabilities affecting oracle/communications_operations_monitor.

Total CVEs
45
CISA KEV
1
actively exploited
Public exploits
6
Exploited in wild
2
Severity breakdown
CRITICAL7HIGH19MEDIUM19

Vulnerabilities

Page 2 of 3
CVE-2021-41184P3MEDIUMCVSS 6.1v4.3v4.4+1 more2021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the val
nvd
CVE-2018-11219P3CRITICALCVSS 9.8v3.4v4.02018-06-17
CVE-2018-11219 [CRITICAL] CWE-190 CVE-2018-11219: An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.
nvd
CVE-2021-41182P3MEDIUMCVSS 6.1v4.3v4.4+1 more2021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
nvd
CVE-2019-16056P3HIGHCVSS 7.5≥ 4.1, ≤ 4.3v3.42019-09-06
CVE-2019-16056 [HIGH] CVE-2019-16056: An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that uses the email module and implements some kind of checks on the From/To headers of a message could be tricked into accepting an email address t
nvd
CVE-2018-16890P3HIGHCVSS 7.5v3.4v4.02019-02-06
CVE-2018-16890 [HIGH] CWE-125 CVE-2018-16890: libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could tr
nvd
CVE-2022-24735P3HIGHCVSS 7.8v4.3v4.4+1 more2022-04-27
CVE-2022-24735 [HIGH] CWE-94 CVE-2022-24735: Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script exe Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution environment in Redis provides some measure
nvd
CVE-2019-7548P3HIGHCVSS 7.8v4.2v4.32019-02-06
CVE-2019-7548 [HIGH] CWE-89 CVE-2019-7548: SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled. SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
nvd
CVE-2019-3823P3HIGHCVSS 7.5v3.4v4.02019-02-06
CVE-2019-3823 [HIGH] CWE-125 CVE-2019-3823: libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the cod libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond the allocated buffer. The read conten
nvd
CVE-2022-21395P3HIGHCVSS 7.2v3.4v4.2+3 more2022-01-19
CVE-2022-21395 [HIGH] CVE-2022-21395: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful attac
nvd
CVE-2020-14147P3HIGHCVSS 7.7v3.4v4.1+2 more2020-06-15
CVE-2020-14147 [HIGH] CVE-2020-14147: An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-depe An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and application crash) or possibly bypass intended sandbox restrictions via a large number, which triggers a stack-based buffer overflow. NOTE: th
nvd
CVE-2021-41183P3MEDIUMCVSS 6.1v4.3v4.4+1 more2021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2016-3513P4MEDIUMCVSS 6.5≤ 3.3.92.0.02016-07-21
CVE-2016-3513 [MEDIUM] CVE-2016-3513: Unspecified vulnerability in the Oracle Communications Operations Monitor component in Oracle Commun Unspecified vulnerability in the Oracle Communications Operations Monitor component in Oracle Communications Applications before 3.3.92.0.0 allows remote authenticated users to affect confidentiality via vectors related to Infrastructure.
nvd
CVE-2022-21401P4MEDIUMCVSS 6.6v3.4v4.2+3 more2022-01-19
CVE-2022-21401 [MEDIUM] CVE-2022-21401: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vuln
nvd
CVE-2022-21399P4MEDIUMCVSS 6.6v3.4v4.2+3 more2022-01-19
CVE-2022-21399 [MEDIUM] CVE-2022-21399: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vuln
nvd
CVE-2022-21403P4MEDIUMCVSS 6.6v3.4v4.2+3 more2022-01-19
CVE-2022-21403 [MEDIUM] CVE-2022-21403: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. While the vuln
nvd
CVE-2019-10219P4MEDIUMCVSS 6.1v3.4v4.2+3 more2019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-15165P4MEDIUMCVSS 5.3v3.4v4.0+3 more2019-10-03
CVE-2019-15165 [MEDIUM] CWE-770 CVE-2019-15165: sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocati sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
nvd
CVE-2022-21397P4MEDIUMCVSS 5.4v3.4v4.2+3 more2022-01-19
CVE-2022-21397 [MEDIUM] CVE-2022-21397: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful atta
nvd
CVE-2022-21246P4MEDIUMCVSS 5.4v3.4v4.2+3 more2022-01-19
CVE-2022-21246 [MEDIUM] CVE-2022-21246: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful atta
nvd
CVE-2022-21400P4MEDIUMCVSS 5.4v3.4v4.2+3 more2022-01-19
CVE-2022-21400 [MEDIUM] CVE-2022-21400: Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (comp Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine). Supported versions that are affected are 3.4, 4.2, 4.3, 4.4 and 5.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Operations Monitor. Successful atta
nvd
Oracle Communications Operations Monitor vulnerabilities | cvebase