VDB

GCVE-110-NCSC-2026-34

GCVE-110-NCSC-2026-34
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published January 22, 2026
Multiple vulnerabilities affect Oracle Communications Unified Assurance and Oracle Business Intelligence Enterprise Edition, allowing denial of service attacks, while older jackson-core versions are prone to StackoverflowErrors when parsing nested data.

Weaknesses (CWE)

CWE-918Server-Side Request Forgery (SSRF)CWE-400Uncontrolled Resource ConsumptionCWE-1333Inefficient Regular Expression ComplexityCWE-787Out-of-bounds WriteCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-20Improper Input ValidationCWE-285Improper AuthorizationCWE-770Allocation of Resources Without Limits or ThrottlingCWE-404Improper Resource Shutdown or ReleaseCWE-287Improper AuthenticationCWE-121Stack-based Buffer OverflowCWE-611Improper Restriction of XML External Entity ReferenceCWE-23Relative Path TraversalCWE-459Incomplete Cleanup

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Atlassianvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›