Oracle

Communications Session Route Manager

74 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.58%
  • Veröffentlicht 31.03.2020 05:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

  • EPSS 3.56%
  • Veröffentlicht 26.03.2020 13:15:13
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.

  • EPSS 3.63%
  • Veröffentlicht 26.03.2020 13:15:12
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).

  • EPSS 3.06%
  • Veröffentlicht 18.03.2020 22:15:12
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).

  • EPSS 8.03%
  • Veröffentlicht 18.03.2020 22:15:12
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).

  • EPSS 18.35%
  • Veröffentlicht 02.03.2020 04:15:11
  • Zuletzt bearbeitet 25.08.2026 16:28:27

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).

  • EPSS 4.61%
  • Veröffentlicht 02.03.2020 04:15:10
  • Zuletzt bearbeitet 07.10.2026 21:17:02

FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).

Exploit
  • EPSS 2.38%
  • Veröffentlicht 17.01.2020 19:15:14
  • Zuletzt bearbeitet 21.11.2024 05:34:03

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vul...

  • EPSS 88.4%
  • Veröffentlicht 17.01.2020 00:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:04

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response...

  • EPSS 7.06%
  • Veröffentlicht 16.01.2020 18:15:11
  • Zuletzt bearbeitet 21.11.2024 04:32:33

By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack, which allows a malicious actor to inject javascript into ...