Known vulnerabilities in Communications Unified Assurance - page 7

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:communications_unified_assurance:*:*:*:*:*:*:*:*
Total vulnerabilities: 145
Public exploits: 22
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Communications Unified Assurance Communications Unified Assurance is affected by 145 known vulnerabilities: 5 critical, 27 high, 88 medium, 25 low Critical High Medium Low

Vulnerabilities (145)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU75044 - Uncontrolled Recursion
CVE-2023-1370
CWE-674 Medium
No
No
- 12.04.2023 SB2023041258
SB2023041259
SB2023041809
and 130 more
#VU72165 - Improper input validation
CVE-2023-0662
CWE-20 Medium
No
No
- 14.02.2023 SB2023021417
SB2023021526
SB2023022245
and 25 more
#VU71242 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-36760
CWE-444 Medium
No
No
- 17.01.2023 SB2023011740
SB2023011805
SB2023012728
and 33 more
#VU70385 - Deserialization of Untrusted Data
CVE-2022-1471
CWE-502 High
Available
No
- 15.12.2022 SB2022121539
SB2022121540
SB2022121928
and 124 more
#VU70332 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-41720
CWE-22 Medium
No
No
- 14.12.2022 SB2022121432
SB2022121433
SB2022121435
and 13 more
#VU69293 - Improper input validation
CVE-2022-3171
CWE-20 Medium
No
No
5.5.10, 6.0.2 14.11.2022 SB2022111433
SB2022111440
SB2022112934
and 105 more
#VU68887 - Integer overflow
CVE-2022-37454
CWE-190 High
Available
No
- 01.11.2022 SB2022110118
SB2022110119
SB2022110209
and 69 more
#VU68859 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-42252
CWE-444 Medium
No
No
- 31.10.2022 SB2022103146
SB2022112324
SB2022112533
and 43 more
#VU68832 - Resource exhaustion
CVE-2022-42004
CWE-400 Medium
No
No
- 31.10.2022 SB2022103116
SB2022103117
SB2022111404
and 122 more
#VU68635 - Deserialization of Untrusted Data
CVE-2022-42003
CWE-502 Medium
No
No
- 25.10.2022 SB2022102509
SB2022102510
SB2022103117
and 208 more
#VU68606 - Improper Verification of Cryptographic Signature
CVE-2020-16156
CWE-347 High
No
No
- 24.10.2022 SB2021121359
SB2022102433
SB2022102701
and 12 more
#VU68307 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-42889
CWE-94 High
Available
Exploited
- 14.10.2022 SB2022101405
SB2022102709
SB2022110306
and 91 more
#VU67945 - Resource exhaustion
CVE-2022-36055
CWE-400 Medium
No
No
- 05.10.2022 SB2022100548
SB2022100551
SB2022102004
and 4 more
#VU65327 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-31081
CWE-444 Medium
No
No
- 14.07.2022 SB2022071425
SB2022071426
SB2022071826
and 14 more
#VU65273 - Improper Check or Handling of Exceptional Conditions
CVE-2022-32212
CWE-703 Medium
No
No
- 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 48 more
#VU63345 - Improper Authorization
CVE-2022-22978
CWE-285 High
Available
No
- 17.05.2022 SB2022051717
SB2022052009
SB2022052010
and 20 more
#VU58270 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-41183
CWE-79 Medium
No
No
- 20.11.2021 SB2021112002
SB2022011943
SB2022011944
and 33 more
#VU27960 - Deserialization of Untrusted Data
CVE-2019-17571
CWE-502 High
No
No
- 18.05.2020 SB2019122027
SB2020051806
SB2020011497
and 28 more
#VU26521 - Permissions, Privileges, and Access Controls
CVE-2020-7009
CWE-264 Medium
No
No
5.5.10, 6.0.2 01.04.2020 SB2020040158
SB20230418141
#VU24218 - Improper input validation
CVE-2019-11287
CWE-20 Medium
No
No
- 13.01.2020 SB2019112307
SB2020011311
SB2021062428
and 5 more


Showing elements 121 - 140 out of 145