Known vulnerabilities in Oracle Communications Policy Management - page 3

Vendor: Oracle
Software CPE: cpe:2.3:a:oracle:oracle_communications_policy_management:*:*:*:*:*:*:*:*
Total vulnerabilities: 56
Public exploits: 16
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Oracle Communications Policy Management Oracle Communications Policy Management is affected by 56 known vulnerabilities: 4 critical, 14 high, 31 medium, 7 low Critical High Medium Low

Vulnerabilities (56)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU77102 - Stack-based buffer overflow
CVE-2022-45688
CWE-121 Medium
No
No
- 08.06.2023 SB2023060836
SB2023060927
SB2023071959
and 35 more
#VU73957 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2023-28708
CWE-614 Low
No
No
- 22.03.2023 SB2023032237
SB2023032939
SB2023032945
and 53 more
#VU72128 - Improper Verification of Cryptographic Signature
CVE-2022-31123
CWE-347 Medium
No
No
- 11.02.2023 SB2023021201
SB2023021202
SB2023021203
and 15 more
#VU70527 - Improper input validation
CVE-2022-41966
CWE-20 Medium
Available
No
- 28.12.2022 SB2022122822
SB2023011211
SB2023020616
and 53 more
#VU69293 - Improper input validation
CVE-2022-3171
CWE-20 Medium
No
No
- 14.11.2022 SB2022111433
SB2022111440
SB2022112934
and 105 more
#VU68635 - Deserialization of Untrusted Data
CVE-2022-42003
CWE-502 Medium
No
No
- 25.10.2022 SB2022102509
SB2022102510
SB2022103117
and 208 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Available
No
- 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU62084 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-31805
CWE-94 High
Available
No
- 12.04.2022 SB2022041218
SB2022061004
SB2022062415
and 10 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
- 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU61756 - Improper Control of Generation of Code ('Code Injection')
CVE-2022-22965
CWE-94 Critical
Available
Exploited
- 31.03.2022 SB2022033109
SB2022040109
SB2022040110
and 78 more
#VU60834 - Improper Control of Generation of Code ('Code Injection')
CVE-2021-23450
CWE-94 High
No
No
- 23.02.2022 SB2022022311
SB2022022312
SB2022031011
and 41 more
#VU60527 - Resource exhaustion
CVE-2021-43859
CWE-400 Medium
No
No
- 11.02.2022 SB2022021102
SB2022021103
SB2022042250
and 26 more
#VU58477 - Heap-based Buffer Overflow
CVE-2021-43527
CWE-122 High
No
No
- 01.12.2021 SB2021120123
SB2021120124
SB2021120201
and 66 more
#VU52252 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2021-29425
CWE-22 Low
No
No
- 15.04.2021 SB2021041510
SB2021081922
SB2021093016
and 121 more
#VU14487 - Improper input validation
CVE-2018-11776
CWE-20 High
Available
Exploited
- 22.08.2018 SB2018082203
SB2020071640
SB2023022240
and 2 more
#VU90 - Exposure of sensitive information to an unauthorized actor
CVE-2015-2808
CWE-200 Medium
No
No
- 05.07.2016 SB2015040102
SB2015040103
SB2023011274
and 27 more


Showing elements 41 - 60 out of 56