Known vulnerabilities in OpenShift API for Data Protection (OADP) - page 15

Software CPE: cpe:2.3:a:red_hat:oadp:*:*:*:*:*:red_hat_openshift_container_platform:*:*
Total vulnerabilities: 307
Public exploits: 18
Known exploited (KEV): 6
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenShift API for Data Protection (OADP) OpenShift API for Data Protection (OADP) is affected by 307 known vulnerabilities: 2 critical, 67 high, 164 medium, 74 low Critical High Medium Low

Vulnerabilities (307)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU66757 - Use After Free
CVE-2022-2526
CWE-416 Medium
No
No
1.0.4 25.08.2022 SB2022082509
SB2022082511
SB2022082531
and 48 more
#VU66189 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-29154
CWE-22 Low
No
No
1.0.4, 1.1.0 08.08.2022 SB2022080837
SB2022081645
SB2022081649
and 70 more
#VU66122 - Use of Insufficiently Random Values
CVE-2022-30629
CWE-330 Medium
No
No
1.0.4, 1.1.0 05.08.2022 SB2022080501
SB2022080503
SB2022081106
and 81 more
#VU66066 - Security Features
CVE-2022-32148
CWE-254 Medium
No
No
1.0.4 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66064 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-1705
CWE-444 Medium
No
No
1.0.4 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66063 - Resource exhaustion
CVE-2022-30630
CWE-400 Medium
No
No
1.0.4 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 79 more
#VU66062 - Resource exhaustion
CVE-2022-30631
CWE-400 Medium
No
No
1.0.4, 1.1.0 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 100 more
#VU64922 - Missing Encryption of Sensitive Data
CVE-2022-2097
CWE-311 Low
No
No
1.0.4, 1.1.0 05.07.2022 SB2022070509
SB2022070522
SB2022070531
and 112 more
#VU64685 - Improper Verification of Cryptographic Signature
CVE-2022-32208
CWE-347 Medium
No
No
1.0.4, 1.1.0 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 73 more
#VU64682 - Resource exhaustion
CVE-2022-32206
CWE-400 Medium
No
No
1.0.4, 1.1.0 27.06.2022 SB2022062711
SB2022062724
SB2022062816
and 80 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
1.0.4, 1.1.0 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU63945 - Out-of-bounds read
CVE-2022-1586
CWE-125 Medium
No
No
1.0.4, 1.1.0 02.06.2022 SB2022060210
SB2022071156
SB2022071217
and 71 more
#VU63747 - Improper Authorization
CVE-2022-26691
CWE-285 High
No
No
1.0.4, 1.1.0 26.05.2022 SB2022052625
SB2022052626
SB2022053018
and 30 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
1.0.4, 1.1.0 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more
#VU62741 - Integer overflow
CVE-2022-29824
CWE-190 High
No
No
1.0.4, 1.1.0 03.05.2022 SB2022050305
SB2022050306
SB2022050307
and 73 more
#VU62002 - Improper input validation
CVE-2022-1271
CWE-20 High
No
No
1.0.4, 1.1.0 08.04.2022 SB2022040803
SB2022040804
SB2022040822
and 134 more
#VU60738 - Integer overflow
CVE-2022-25314
CWE-190 Medium
No
No
1.0.4, 1.1.0 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 68 more
#VU60737 - Stack-based buffer overflow
CVE-2022-25313
CWE-121 High
No
No
1.0.4, 1.1.0 21.02.2022 SB2022022109
SB2022022113
SB2022022411
and 64 more
#VU56685 - Use of a Broken or Risky Cryptographic Algorithm
CVE-2021-40528
CWE-327 Medium
No
No
1.0.4, 1.1.0 17.09.2021 SB2021091710
SB2021091711
SB2021091629
and 44 more
#VU56217 - Memory corruption
CVE-2021-3634
CWE-119 High
No
No
1.0.4, 1.1.0 31.08.2021 SB2021083135
SB2021083136
SB2022011903
and 46 more


Showing elements 281 - 300 out of 307