Vulnerabilities > Oracle > Communications Messaging Server > 8.0

DATE CVE VULNERABILITY TITLE RISK
2017-04-17 CVE-2017-5645 Deserialization of Untrusted Data vulnerability in multiple products
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
network
low complexity
apache netapp redhat oracle CWE-502
critical
9.8
2016-07-21 CVE-2016-5455 Remote Security vulnerability in Oracle Communications Messaging Server 6.3/7.0/8.0
Unspecified vulnerability in the Oracle Communications Messaging Server component in Oracle Communications Applications 6.3, 7.0, and 8.0 allows remote attackers to affect confidentiality via vectors related to Multiplexor.
network
low complexity
oracle
5.0