Oracle / Communications Instant Messaging Server
57 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-13935 | tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-13934 | tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS | HIGH | 7.5 | Jul 14, 2020 |
| CVE-2020-14195 | jackson-databind: serialization in org.jsecurity.realm.jndi.JndiRealmFactory | HIGH | 8.1 | Jun 16, 2020 |
| CVE-2020-14061 | jackson-databind: serialization in weblogic/oracle-aqjms | HIGH | 8.1 | Jun 14, 2020 |
| CVE-2020-9484 | tomcat: deserialization flaw in session persistence storage leading to RCE | HIGH | 7.0 | May 20, 2020 |
| CVE-2020-11620 | jackson-databind: Serialization gadgets in commons-jelly:commons-jelly | HIGH | 8.1 | Apr 7, 2020 |
| CVE-2020-11619 | jackson-databind: Serialization gadgets in org.springframework:spring-aop | HIGH | 8.1 | Apr 7, 2020 |
| CVE-2020-11111 | jackson-databind: Serialization gadgets in org.apache.activemq.jms.pool.XaPooledConnectionFactory | HIGH | 8.8 | Mar 31, 2020 |
| CVE-2020-11112 | jackson-databind: Serialization gadgets in org.apache.commons.proxy.provider.remoting.RmiProvider | HIGH | 8.8 | Mar 31, 2020 |
| CVE-2020-11113 | jackson-databind: Serialization gadgets in org.apache.openjpa.ee.WASRegistryManagedRuntime | HIGH | 8.8 | Mar 31, 2020 |
| CVE-2020-10968 | jackson-databind: Serialization gadgets in org.aoju.bus.proxy.provider.*.RmiProvider | HIGH | 8.8 | Mar 26, 2020 |
| CVE-2020-10969 | jackson-databind: Serialization gadgets in javax.swing.JEditorPane | HIGH | 8.8 | Mar 26, 2020 |
| CVE-2020-10672 | jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution | HIGH | 8.8 | Mar 18, 2020 |
| CVE-2020-10673 | jackson-databind: mishandles the interaction between serialization gadgets and typing which could result in remote command execution | HIGH | 8.8 | Mar 18, 2020 |
| CVE-2020-9546 | jackson-databind: Serialization gadgets in shaded-hikari-config | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2020-9547 | jackson-databind: Serialization gadgets in ibatis-sqlmap | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2020-9548 | jackson-databind: Serialization gadgets in anteros-core | CRITICAL | 9.8 | Mar 2, 2020 |
| CVE-2020-1938 KEV | tomcat: Apache Tomcat AJP File Read/Inclusion Vulnerability | CRITICAL | 9.8 | Feb 24, 2020 |
| CVE-2020-1935 | tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2019-17569 | tomcat: Regression in handling of Transfer-Encoding header allows for HTTP request smuggling | MEDIUM | 4.8 | Feb 24, 2020 |
| CVE-2019-20330 | jackson-databind: lacks certain net.sf.ehcache blocking | CRITICAL | 9.8 | Jan 3, 2020 |
| CVE-2019-10219 | hibernate-validator: safeHTML validator allows XSS | MEDIUM | 6.1 | Nov 8, 2019 |
| CVE-2019-14439 | jackson-databind: Polymorphic typing issue related to logback/JNDI | HIGH | 7.5 | Jul 30, 2019 |
| CVE-2019-14379 | jackson-databind: default typing mishandling leading to remote code execution | CRITICAL | 9.8 | Jul 29, 2019 |
| CVE-2018-11307 | jackson-databind: Potential information exfiltration with default typing, serialization gadget from MyBatis | CRITICAL | 9.8 | Jul 9, 2019 |
Showing 26 to 50 of 57 CVEs