Comparison Overview
Carelon Research

Carelon Research
123 Justison Street, Wilmington, 19801, US
Last Update: 05/03/2026
Carelon Research is the trusted partner for healthcare research. As a subsidiary of Elevance Health, one of the nation’s largest health insurers, we work with life sciences companies, government agencies, and academic research leaders to solve healthcare challenges with...

Technical University of Munich
Arcisstraße 21, München, Munich, Bavaria, DE, 80333
Last Update: 02/04/2026
Our university combines top-class facilities for cutting-edge research with unique learning opportunities for 52,000 students. Whether our researchers are investigating the origins of life, matter and the universe or looking for solutions to the major challenges for our...
Compliance Ranges Comparison

Carelon Research







Technical University of Munich






Benchmark & Cyber Underwriting Signals
Incidents vs Research Services Industry Avg (This Year)
No incidents recorded for Carelon Research in 2026.
Incidents vs Research Services Industry Avg (This Year)
No incidents recorded for Technical University of Munich in 2026.
Incident History - Carelon Research (X = Date, Y = Severity)
Carelon Research cyber incidents detection timeline including parent company and subsidiaries.
Incident History - Technical University of Munich (X = Date, Y = Severity)
Technical University of Munich cyber incidents detection timeline including parent company and subsidiaries.
Notable Incidents

Carelon Research

Technical University of Munich
FAQ
Latest Global CVEs
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApplyOplogUpdate can be executed by any authenticated user with access to the aggregate command.
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS. Strict-winding polygons are intentionally unsupported for indexing, but the guard that rejects them does not inspect members of a GeometryCollection, allowing the unsafe path to be reached which ends with an ensuing null-pointer dereference.
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-controlled document fields and internal metadata in certain execution paths.