Known Vulnerabilities for Communications Instant Messaging Server by Oracle
Listed below are 10 of the newest known vulnerabilities associated with "Communications Instant Messaging Server" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-23307 json | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a c... | 8.8 - HIGH | 2022-01-18 | 2023-02-24 |
| CVE-2022-23305 json | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inser... | 9.8 - CRITICAL | 2022-01-18 | 2023-02-24 |
| CVE-2022-23302 json | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to... | 8.8 - HIGH | 2022-01-18 | 2023-02-24 |
| CVE-2021-43797 json | Netty is an asynchronous event-driven network application framework for rapid development of maintainable high performance pr... | 6.5 - MEDIUM | 2021-12-09 | 2023-02-24 |
| CVE-2021-37136 json | The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affec... | 7.5 - HIGH | 2021-10-19 | 2023-11-07 |
| CVE-2021-33037 json | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding ... | 5.3 - MEDIUM | 2021-07-12 | 2023-11-07 |
| CVE-2021-25329 json | The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 o... | 7 - HIGH | 2021-03-01 | 2023-11-07 |
| CVE-2021-25122 json | When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8... | 7.5 - HIGH | 2021-03-01 | 2023-11-07 |
| CVE-2020-36189 json | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... | 8.1 - HIGH | 2021-01-06 | 2023-09-13 |
| CVE-2020-36188 json | FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related t... | 8.1 - HIGH | 2021-01-06 | 2023-09-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Communications Instant Messaging Server | 9.0.2 | |||
| Application | Oracle | Communications Instant Messaging Server | 9.0.1 | |||
| Application | Oracle | Communications Instant Messaging Server | 8.0 | |||
| Application | Oracle | Communications Instant Messaging Server | 10.0.1.4.0 | |||
| Application | Oracle | Communications Instant Messaging Server | 10.0.1.2.0 | |||
| Application | Oracle | Communications Instant Messaging Server | 10.0.1 | |||
| Application | Oracle | Communications Instant Messaging Server | 10.0 |