Known vulnerabilities in Oracle Communications Policy Management - page 2

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_communications_policy_management:*:*:*:*:*:*:*:*
Total vulnerabilities: 56
Public exploits: 16
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Communications Policy Management Oracle Communications Policy Management is affected by 56 known vulnerabilities: 4 critical, 14 high, 31 medium, 7 low Critical High Medium Low

Vulnerabilities (56)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU107497 - Improper input validation
CVE-2024-4227
CWE-20 Medium
No
No
- 16.04.2025 SB2025041690
SB20250416102
SB2026012379
#VU101893 - Permissions, Privileges, and Access Controls
CVE-2024-56337
CWE-264 High
No
No
- 20.12.2024 SB2024122063
SB2025011311
SB2025011801
and 45 more
#VU101653 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-53677
CWE-22 High
Available
No
- 11.12.2024 SB2024121136
SB2025012198
SB2025041017
and 2 more
#VU100095 - Memory corruption
CVE-2024-47072
CWE-119 Medium
No
No
- 07.11.2024 SB20241107102
SB20241115126
SB2024112531
and 36 more
#VU98025 - Resource exhaustion
CVE-2024-47554
CWE-400 Medium
No
No
- 03.10.2024 SB2024100352
SB2024100421
SB2024101007
and 132 more
#VU92262 - Exposure of sensitive information to an unauthorized actor
CVE-2024-37891
CWE-200 Low
No
No
- 19.06.2024 SB2024061955
SB20240625146
SB2024062605
and 194 more
#VU90156 - Security Features
CVE-2024-35195
CWE-254 Low
No
No
- 31.05.2024 SB2024053174
SB2024053188
SB2024053192
and 117 more
#VU88063 - Memory corruption
CVE-2024-28219
CWE-119 Medium
No
No
- 03.04.2024 SB2024040318
SB2024040320
SB2024040844
and 28 more
#VU87671 - Cryptographic Issues
CVE-2024-28834
CWE-310 Medium
No
No
- 20.03.2024 SB2024032057
SB2024032058
SB2024032059
and 111 more
#VU87509 - Resource exhaustion
CVE-2024-23672
CWE-400 Medium
No
No
- 13.03.2024 SB2024031386
SB2024032821
SB2024032824
and 49 more
#VU83960 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-50164
CWE-22 High
Available
Exploited
- 07.12.2023 SB2023120703
SB2023121830
SB2024011029
and 7 more
#VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-46589
CWE-444 Medium
No
No
- 28.11.2023 SB2023112846
SB2023121851
SB2023122831
and 78 more
#VU82276 - Allocation of Resources Without Limits or Throttling
CVE-2023-5072
CWE-770 Medium
No
No
- 20.10.2023 SB2023102017
SB2023102018
SB2023113056
and 97 more
#VU80089 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2023-41080
CWE-601 Medium
Available
No
- 29.08.2023 SB2023082924
SB2023100565
SB2023101122
and 51 more
#VU78454 - Untrusted Search Path
CVE-2023-38408
CWE-426 Medium
Available
No
- 20.07.2023 SB2023072068
SB2023072073
SB2023072074
and 73 more
#VU77227 - Resource exhaustion
CVE-2023-34396
CWE-400 Medium
No
No
- 13.06.2023 SB2023061351
SB2023070502
SB2023071316
and 12 more
#VU77107 - Incorrect Default Permissions
CVE-2023-2976
CWE-276 Low
No
No
- 08.06.2023 SB2023060849
SB2023071712
SB2023072512
and 157 more
#VU70531 - Deserialization of Untrusted Data
CVE-2022-36944
CWE-502 High
Available
No
- 28.12.2022 SB2022122829
SB2022122924
SB2023021531
and 15 more
#VU69809 - Out-of-bounds write
CVE-2022-42920
CWE-787 High
No
No
- 01.12.2022 SB2022120151
SB2022120154
SB2022120628
and 56 more
#VU65495 - Improper input validation
CVE-2022-34169
CWE-20 High
Available
No
- 20.07.2022 SB2022072046
SB2022072047
SB2022072140
and 137 more


Showing elements 21 - 40 out of 56