cbcvebase.

Oracle Communications Policy Management vulnerabilities

50 known vulnerabilities affecting oracle/communications_policy_management.

Total CVEs
50
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL13HIGH23MEDIUM13LOW1

Vulnerabilities

Page 3 of 3
CVE-2021-29425P4MEDIUMCVSS 4.8v12.5.0.0.02021-04-13
CVE-2021-29425 [MEDIUM] CWE-20 CVE-2021-29425: In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper i In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to constru
nvd
CVE-2015-2568P4MEDIUMCVSS 5.0≤ 9.7.3v9.9.1+2 more2015-04-16
CVE-2015-2568 [MEDIUM] CVE-2015-2568: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2020-5397P4MEDIUMCVSS 5.3v12.5.02020-01-17
CVE-2020-5397 [MEDIUM] CWE-352 CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS prefligh Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail au
nvd
CVE-2015-0382P4MEDIUMCVSS 4.3≤ 9.7.3v9.9.1+2 more2015-01-21
CVE-2015-0382 [MEDIUM] CVE-2015-0382: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
nvd
CVE-2017-10159P4MEDIUMCVSS 6.1v11.5v12.02017-10-19
CVE-2017-10159 [MEDIUM] CVE-2017-10159: Vulnerability in the Oracle Communications Policy Management component of Oracle Communications Appl Vulnerability in the Oracle Communications Policy Management component of Oracle Communications Applications (subcomponent: Portal, CMP). Supported versions that are affected are 11.5 and 12.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management. Successful attac
nvd
CVE-2015-0381P4MEDIUMCVSS 4.3≤ 9.7.3v9.9.1+2 more2015-01-21
CVE-2015-0381 [MEDIUM] CVE-2015-0381: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.
nvd
CVE-2015-0433P4MEDIUMCVSS 4.0≤ 9.7.3v9.9.1+2 more2015-04-16
CVE-2015-0433 [MEDIUM] CVE-2015-0433: Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
nvd
CVE-2015-0409P4MEDIUMCVSS 4.0≤ 9.7.3v9.9.1+2 more2015-01-21
CVE-2015-0409 [MEDIUM] CVE-2015-0409: Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.21 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
CVE-2015-0500P4MEDIUMCVSS 4.0≤ 9.7.3v9.9.1+2 more2015-04-16
CVE-2015-0500 [MEDIUM] CVE-2015-0500: Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
nvd
CVE-2015-0423P4MEDIUMCVSS 4.0≤ 9.7.3v9.9.1+2 more2015-04-16
CVE-2015-0423 [MEDIUM] CVE-2015-0423: Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated user Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
nvd
Oracle Communications Policy Management vulnerabilities | cvebase