Vulnerabilities > Oracle > Communications Cloud Native Core Network Function Cloud Native Environment > 1.7.0

DATE CVE VULNERABILITY TITLE RISK
2020-09-16 CVE-2020-7733 Resource Exhaustion vulnerability in multiple products
The package ua-parser-js before 0.7.22 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex for Redmi Phones and Mi Pad Tablets UA.
network
low complexity
ua-parser-js-project oracle CWE-400
7.5
2020-07-27 CVE-2020-7017 Cross-site Scripting vulnerability in multiple products
In Kibana versions before 6.8.11 and 7.8.1 the region map visualization in contains a stored XSS flaw.
network
high complexity
elasticsearch oracle CWE-79
6.7
2020-07-27 CVE-2020-7016 Resource Exhaustion vulnerability in multiple products
Kibana versions before 6.8.11 and 7.8.1 contain a denial of service (DoS) flaw in Timelion.
network
high complexity
elasticsearch oracle CWE-400
4.8