Communications brm - elastic charging engine
This hub aggregates every CVE we track for Communications brm - elastic charging engine, a product in the communications space. Use it to gauge the current risk picture and drill into individual advisories.
18
CVEs tracked
1
Critical
9
High
1
In CISA KEV
Severity distribution
HIGH9MEDIUM8CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Communications brm - elastic charging engine.
- CVE-2023-21824Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are a...4.4
- CVE-2021-43859Denial of Service by injecting highly recursive collections or maps in XStream7.5
- CVE-2021-44832Apache Log4j2 vulnerable to RCE via JDBC Appender when attacker controls configuration6.6
- CVE-2021-37136The Bzip2 decompression decoder function doesn't allow setting size restrictions on the decompressed output data (which affects the allocation size used during decompression). All users of Bzip2Dec...7.5
- CVE-2021-37137The Snappy frame decoder function doesn't restrict the chunk length which may lead to excessive memory usage. Beside this it also may buffer reserved skippable chunks until the whole chunk was rece...7.5
- CVE-2021-38153Timing Attack Vulnerability for Apache Kafka Connect and Clients5.9
- CVE-2021-39144XStream is vulnerable to a Remote Command Execution attackKEV8.5
- CVE-2021-29505XStream is vulnerable to a Remote Command Execution attack7.5
- CVE-2021-22118In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory...7.8
- CVE-2021-21409Possible request smuggling in HTTP/2 due missing validation of content-length5.9
- CVE-2021-21342A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host5.3
- CVE-2021-21290Local Information Disclosure Vulnerability in Netty on Unix-Like systems due temporary files6.2
- CVE-2020-17521Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method...5.5
- CVE-2020-11612The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty ser...7.5
- CVE-2020-5397CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux5.3
Product normalization is registry-driven with AI assist and human review. How it works