« Back to list

Oracle

Oracle Communications Communications Policy Management: vulnerabilities and CVEs

Oracle Communications Communications Policy Management has 3 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 1 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical2
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-22963Critical (9.8)100%⚠ Active exploitationApr 1, 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-22963Critical (9.8)100%⚠ Active exploitationApr 1, 2022
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in…
CVE-2021-3449Medium (5.9)64%—Mar 25, 2021
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the…
CVE-2017-7525Critical (9.8)38%—Feb 6, 2018
A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to…

Other products by Oracle