Known vulnerabilities in Oracle Communications Policy Management

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_communications_policy_management:*:*:*:*:*:*:*:*
Total vulnerabilities: 56
Public exploits: 16
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Communications Policy Management Oracle Communications Policy Management is affected by 56 known vulnerabilities: 4 critical, 14 high, 31 medium, 7 low Critical High Medium Low

Vulnerabilities (56)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU122999 - Improper Authorization
CVE-2026-24734
CWE-285 Medium
No
No
- 17.02.2026 SB2026021766
SB2026030536
SB2026031245
and 24 more
#VU122489 - Heap-based Buffer Overflow
CVE-2026-25646
CWE-122 High
No
No
- 10.02.2026 SB2026021002
SB2026021255
SB2026021256
and 64 more
#VU121072 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-21441
CWE-409 Medium
No
No
- 07.01.2026 SB2026010780
SB2026011269
SB2026011328
and 89 more
#VU120607 - Stack-based buffer overflow
CVE-2025-68615
CWE-121 Critical
No
No
- 26.12.2025 SB20251226349
SB2026010785
SB2026011301
and 43 more
#VU120231 - Improper Validation of Certificate with Host Mismatch
CVE-2025-68161
CWE-297 Medium
No
No
- 22.12.2025 SB2025122245
SB2026012084
SB2026012087
and 101 more
#VU117682 - Resource exhaustion
CVE-2025-61795
CWE-400 Medium
No
No
- 27.10.2025 SB2025102749
SB20251031122
SB20251031123
and 39 more
#VU116882 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2025-61984
CWE-78 Low
No
No
- 10.10.2025 SB2025101008
SB2025103199
SB20251031100
and 27 more
#VU116196 - Memory corruption
CVE-2025-9900
CWE-119 High
No
No
- 30.09.2025 SB2025093033
SB2025093035
SB2025100921
and 50 more
#VU113607 - Uncontrolled Recursion
CVE-2025-48924
CWE-674 Medium
No
No
- 04.08.2025 SB2025080422
SB2025080423
SB2025080427
and 180 more
#VU112994 - NULL Pointer Dereference
CVE-2025-32990
CWE-476 Low
No
No
- 16.07.2025 SB20250716122
SB20250716123
SB20250716124
and 79 more
#VU111900 - Out-of-bounds read
CVE-2025-5318
CWE-125 Medium
No
No
- 24.06.2025 SB2025062451
SB2025062454
SB20250704157
and 61 more
#VU111165 - Improper Access Control
CVE-2025-48734
CWE-284 Medium
No
No
- 16.06.2025 SB2025061643
SB2025061644
SB2025061645
and 141 more
#VU111162 - Resource exhaustion
CVE-2025-48976
CWE-400 Medium
Available
No
- 16.06.2025 SB2025061634
SB2025061635
SB2025061927
and 156 more
#VU111161 - Resource exhaustion
CVE-2025-48988
CWE-400 Medium
Available
No
- 16.06.2025 SB2025061634
SB2025061927
SB20250620145
and 40 more
#VU105715 - Out-of-bounds write
CVE-2025-27363
CWE-787 Critical
Available
Exploited
- 14.03.2025 SB2025031402
SB2025031502
SB2025031750
and 97 more
#VU105485 - Improper input validation
CVE-2025-24813
CWE-20 Critical
Available
Exploited
- 10.03.2025 SB2025031069
SB2025031976
SB2025032642
and 48 more
#VU103980 - Resource exhaustion
CVE-2024-12133
CWE-400 Medium
No
No
- 14.02.2025 SB2025021428
SB2025021429
SB2025021430
and 78 more
#VU98498 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2024-28168
CWE-611 Medium
No
No
- 14.10.2024 SB2024101462
SB2024101465
SB2024112829
and 18 more
#VU95780 - Improper Access Control
CVE-2024-43044
CWE-284 High
Available
No
- 12.08.2024 SB2024081207
SB20241015131
SB20241015132
and 5 more
#VU85267 - Covert Timing Channel
CVE-2023-5388
CWE-385 Medium
No
No
- 10.01.2024 SB2024011031
SB2024011042
SB2024011043
and 96 more


Showing elements 1 - 20 out of 56