Oracle / Communications Instant Messaging Server
57 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-23307 | A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution. | CRITICAL | 9.8 | Jan 18, 2022 |
| CVE-2022-23305 | SQL injection in JDBC Appender in Apache Log4j V1 | CRITICAL | 9.8 | Jan 18, 2022 |
| CVE-2022-23302 | Deserialization of untrusted data in JMSSink in Apache Log4j 1.x | HIGH | 8.8 | Jan 18, 2022 |
| CVE-2021-43797 | HTTP fails to validate against control chars in header names which may lead to HTTP request smuggling | MEDIUM | 6.5 | Dec 9, 2021 |
| CVE-2021-37136 | netty-codec: Bzip2Decoder doesn't allow setting size restrictions for decompressed data | HIGH | 7.5 | Oct 19, 2021 |
| CVE-2021-33037 | Incorrect Transfer-Encoding handling with HTTP/1.0 | MEDIUM | 5.3 | Jul 12, 2021 |
| CVE-2021-25329 | Incomplete fix for CVE-2020-9484 | HIGH | 7.0 | Mar 1, 2021 |
| CVE-2021-25122 | Apache Tomcat h2c request mix-up | HIGH | 7.5 | Mar 1, 2021 |
| CVE-2020-36179 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36180 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36182 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36183 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36184 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-36185 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36186 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36187 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36188 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnection… | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36189 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerC… | HIGH | 8.1 | Jan 6, 2021 |
| CVE-2020-36181 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS | HIGH | 8.8 | Jan 6, 2021 |
| CVE-2020-35490 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource | HIGH | 8.1 | Dec 17, 2020 |
| CVE-2020-35491 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource | HIGH | 8.1 | Dec 17, 2020 |
| CVE-2020-17527 | Apache Tomcat: Request header mix-up between HTTP/2 streams | HIGH | 7.5 | Dec 3, 2020 |
| CVE-2020-25649 | jackson-databind: FasterXML DOMDeserializer insecure entity expansion is vulnerable to XML external entity (XXE) | HIGH | 7.5 | Dec 3, 2020 |
| CVE-2020-24750 | jackson-databind: Serialization gadgets in com.pastdev.httpcomponents.configuration.JndiConfiguration | HIGH | 8.1 | Sep 17, 2020 |
| CVE-2020-24616 | jackson-databind: mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource | HIGH | 8.1 | Aug 25, 2020 |
Showing 1 to 25 of 57 CVEs