Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Er zijn kwetsbaarheden verholpen in Oracle Siebel CRM.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Toegang tot gevoelige gegevens
- Toegang tot systeemgegevens
- Manipulatie van gegevens
- (Remote) code execution (Gebruikersrechten)
- Oplossingen
Oracle heeft updates beschikbaar gesteld om de kwetsbaarheden te verhelpen. Zie de referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
- CWE-158
Improper Neutralization of Null Byte or NUL Character
- CWE-192
Integer Coercion Error
- CWE-20
Improper Input Validation
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-295
Improper Certificate Validation
- CWE-325
Missing Cryptographic Step
- CWE-404
Improper Resource Shutdown or Release
- CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- CWE-502
Deserialization of Untrusted Data
- CWE-681
Incorrect Conversion between Numeric Types
- CWE-754
Improper Check for Unusual or Exceptional Conditions
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-787
Out-of-bounds Write
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard