Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0298

Published Jul 17, 2024·Last modified Jul 17, 2024
Description
Feiten

Er zijn kwetsbaarheden verholpen in Oracle Fusion Middleware.

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Toegang tot gevoelige gegevens
  • Toegang tot systeemgegevens
  • Manipulatie van gegevens
  • (Remote) code execution (Gebruikersrechten)
Oplossingen

Oracle heeft updates beschikbaar gesteld om de kwetsbaarheden te verhelpen. Zie de referenties voor meer informatie.

Kans

medium

Schade

high

CWE-122

Heap-based Buffer Overflow

CWE-145

Improper Neutralization of Section Delimiters

CWE-190

Integer Overflow or Wraparound

CWE-20

Improper Input Validation

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-222

Truncation of Security-relevant Information

CWE-284

Improper Access Control

CWE-299

Improper Check for Certificate Revocation

CWE-306

Missing Authentication for Critical Function

CWE-328

Use of Weak Hash

CWE-377

Insecure Temporary File

CWE-400

Uncontrolled Resource Consumption

CWE-404

Improper Resource Shutdown or Release

CWE-416

Use After Free

CWE-552

Files or Directories Accessible to External Parties

CWE-601

URL Redirection to Untrusted Site ('Open Redirect')

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-787

Out-of-bounds Write

CWE-918

Server-Side Request Forgery (SSRF)

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard