Oracle
Oracle Communications Billing AND Revenue Management Elastic Charging Engine: vulnerabilidades y CVE
Oracle Communications Billing AND Revenue Management Elastic Charging Engine tiene 31 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 7 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE31
Últimos 12 meses1
Críticas7
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-39144 | Alta (8.5) | 98% | ⚠ Explotación activa | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-61053 | Alta (7.8) | 0.16% | — | 21 jul 2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications (component: Diameter Gateway and SDK). Supported versions that are affected are 15.0.0.0.0, 15.0.1.0.0,… |
| CVE-2023-21824 | Media (4.4) | 0.21% | — | 18 ene 2023 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are… |
| CVE-2021-39152 | Alta (8.5) | 11% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by… |
| CVE-2021-39150 | Alta (8.5) | 3.4% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to request data from internal resources that are not publicly available only by… |
| CVE-2021-39140 | Media (6.3) | 5.9% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or… |
| CVE-2021-39154 | Alta (8.5) | 4.7% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39153 | Alta (8.5) | 4.5% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39151 | Alta (8.5) | 4.7% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39149 | Alta (8.5) | 4.7% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39148 | Alta (8.5) | 4.7% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39147 | Alta (8.5) | 4.7% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39146 | Alta (8.5) | 14% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39145 | Alta (8.5) | 4.1% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39144 | Alta (8.5) | 98% | ⚠ Explotación activa | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the… |
| CVE-2021-39141 | Alta (8.5) | 16% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-39139 | Alta (8.8) | 4.5% | — | 23 ago 2021 | XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the… |
| CVE-2021-29425 | Media (4.8) | 9.9% | — | 13 abr 2021 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to… |
| CVE-2021-21351 | Crítica (9.1) | 82% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by… |
| CVE-2021-21350 | Crítica (9.8) | 15% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to execute arbitrary code only by manipulating the… |
| CVE-2021-21349 | Alta (8.6) | 47% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to request data from internal resources that are not… |
| CVE-2021-21348 | Alta (7.5) | 14% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and… |
| CVE-2021-21347 | Crítica (9.8) | 14% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21346 | Crítica (9.8) | 76% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21345 | Crítica (9.9) | 72% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the… |
| CVE-2021-21344 | Crítica (9.8) | 76% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host… |
| CVE-2021-21343 | Alta (7.5) | 47% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability where the processed stream at unmarshalling time contains type information to recreate the… |
| CVE-2021-21341 | Alta (7.5) | 78% | — | 23 mar 2021 | XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is vulnerability which may allow a remote attacker to allocate 100% CPU time on the target system depending… |
| CVE-2020-5398 | Alta (7.5) | 89% | — | 17 ene 2020 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a… |
| CVE-2019-10219 | Media (6.1) | 2.2% | — | 8 nov 2019 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can… |
| CVE-2019-10086 | Alta (7.3) | 28% | — | 20 ago 2019 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.