Oracle Communications Messaging Server 8.0.2

CPE Details

Oracle Communications Messaging Server 8.0.2
8.0.2
2019-07-01
14h22 +00:00
2019-07-01
14h22 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:o:oracle:communications_messaging_server:8.0.2:*:*:*:*:*:*:*

Informations

Vendor

oracle

Product

communications_messaging_server

Version

8.0.2

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-28052 2020-12-17 23h52 +00:00 An issue was discovered in Legion of the Bouncy Castle BC Java 1.65 and 1.66. The OpenBSDBCrypt.checkPassword utility method compared incorrect data when checking the password, allowing incorrect passwords to indicate they were matching with previously hashed ones that were different.
8.1
High
CVE-2020-25649 2020-12-03 15h16 +00:00 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
7.5
High
CVE-2020-13954 2020-11-12 12h45 +00:00 By default, Apache CXF creates a /services page containing a listing of the available endpoint names and addresses. This webpage is vulnerable to a reflected Cross-Site Scripting (XSS) attack via the styleSheetPath, which allows a malicious actor to inject javascript into the web page. This vulnerability affects all versions of Apache CXF prior to 3.4.1 and 3.3.8. Please note that this is a separate issue to CVE-2019-17573.
6.1
Medium