Known vulnerabilities in Oracle Communications Instant Messaging Server - page 3

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_communications_messaging_server:*:*:*:*:*:*:*:*
Total vulnerabilities: 61
Public exploits: 7
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Communications Instant Messaging Server Oracle Communications Instant Messaging Server is affected by 61 known vulnerabilities: 1 critical, 13 high, 41 medium, 6 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU52252 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-29425
CWE-22 Low
No
No
- 15.04.2021 SB2021041510
SB2021081922
SB2021093016
and 121 more
#VU51796 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2021-28657
CWE-835 Medium
No
No
- 30.03.2021 SB2021033021
SB2022042284
SB2021062232
and 4 more
#VU49857 - Improper input validation
CVE-2020-13954
CWE-20 Medium
No
No
- 20.01.2021 SB2021012079
SB2021042320
SB2021120219
and 7 more
#VU49086 - Comparison using wrong factors
CVE-2020-28052
CWE-1025 High
Available
No
- 18.12.2020 SB2020121801
SB2021031707
SB2021042112
and 16 more
#VU29128 - Deserialization of Untrusted Data
CVE-2020-14195
CWE-502 High
Available
No
- 18.06.2020 SB2020061806
SB2020070320
SB2020102703
and 24 more
#VU28773 - Use After Free
CVE-2020-13871
CWE-416 High
No
No
- 07.06.2020 SB2020060705
SB2020072756
SB2020102002
and 8 more
#VU28194 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2019-0228
CWE-611 Medium
No
No
- 24.05.2020 SB2019041716
SB2021042320
SB2021042642
and 4 more
#VU28158 - Deserialization of Untrusted Data
CVE-2020-9484
CWE-502 High
Available
No
- 21.05.2020 SB2020052124
SB2020052501
SB2020053102
and 47 more
#VU27513 - Resource exhaustion
CVE-2020-11612
CWE-400 Medium
No
No
- 04.05.2020 SB2020050435
SB2020073033
SB2021012210
and 35 more
#VU27487 - Improper Certificate Validation
CVE-2020-9488
CWE-295 Low
No
No
- 04.05.2020 SB2020050406
SB2020071606
SB2020071620
and 67 more
#VU34420 - Missing release of memory after effective lifetime
CVE-2020-9489
CWE-401 Medium
No
No
- 27.04.2020 SB2020042727
SB2020102706
SB2020102845
and 2 more
#VU26470 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2020-1951
CWE-835 Medium
No
No
- 31.03.2020 SB2020033108
SB2020071605
SB2020102927
and 3 more
#VU25830 - Deserialization of Untrusted Data
CVE-2020-9546
CWE-502 High
No
No
- 09.03.2020 SB2020030909
SB2020071523
SB2020071620
and 31 more
#VU25502 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2020-1938
CWE-22 High
Available
Exploited
- 21.02.2020 SB2020022111
SB2020031401
SB2020031402
and 31 more
#VU24494 - Improper input validation
CVE-2019-10088
CWE-20 High
No
No
- 22.01.2020 SB2020012309
SB2020042111
SB2020041458
and 1 more
#VU20992 - Resource Management Errors
CVE-2019-10072
CWE-399 Medium
No
No
- 10.09.2019 SB2019091025
SB2019112011
SB2019112012
and 14 more
#VU19933 - Permissions, Privileges, and Access Controls
CVE-2019-14379
CWE-264 High
No
No
- 05.08.2019 SB2019091307
SB2019092703
SB2019100116
and 33 more
#VU16676 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2018-17197
CWE-835 Low
No
No
- 22.12.2018 SB2018122407
SB2020042337
SB2019071640
and 2 more
#VU12127 - Deserialization of Untrusted Data
CVE-2017-5645
CWE-502 High
No
No
- 24.04.2018 SB2017040201
SB2019011707
SB2017090512
and 40 more
#VU10706 - Permissions, Privileges, and Access Controls
CVE-2018-1305
CWE-264 Low
No
No
- 26.02.2018 SB2018022601
SB2018032308
SB2018032107
and 8 more


Showing elements 41 - 60 out of 61