Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0411

Published Oct 17, 2024·Last modified Oct 17, 2024
Description
Feiten

Oracle heeft kwetsbaarheden verholpen in diverse Database producten en subsystemen, zoals de Core database, Application Express, Autonomous Health Framework, Essbase, GoldenGate, SQL Developer en Secure Backup.

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:

  • Denial-of-Service (DoS)
  • Manipuleren van data
  • Toegang tot gevoelige gegevens
Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-130

Improper Handling of Length Parameter Inconsistency

CWE-208

Observable Timing Discrepancy

CWE-776

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

CWE-755

Improper Handling of Exceptional Conditions

CWE-834

Excessive Iteration

CWE-407

Inefficient Algorithmic Complexity

CWE-178

Improper Handling of Case Sensitivity

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-415

Double Free

CWE-311

Missing Encryption of Sensitive Data

CWE-427

Uncontrolled Search Path Element

CWE-172

Encoding Error

CWE-680

Integer Overflow to Buffer Overflow

CWE-426

Untrusted Search Path

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

CWE-116

Improper Encoding or Escaping of Output

CWE-345

Insufficient Verification of Data Authenticity

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-203

Observable Discrepancy

CWE-190

Integer Overflow or Wraparound

CWE-552

Files or Directories Accessible to External Parties

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-125

Out-of-bounds Read

CWE-404

Improper Resource Shutdown or Release

CWE-275

CWE-275

CWE-284

Improper Access Control

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-1333

Inefficient Regular Expression Complexity

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-416

Use After Free

CWE-401

Missing Release of Memory after Effective Lifetime

CWE-476

NULL Pointer Dereference

CWE-295

Improper Certificate Validation

CWE-668

Exposure of Resource to Wrong Sphere

CWE-829

Inclusion of Functionality from Untrusted Control Sphere

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-502

Deserialization of Untrusted Data

CWE-918

Server-Side Request Forgery (SSRF)

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-787

Out-of-bounds Write

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-122

Heap-based Buffer Overflow

CWE-121

Stack-based Buffer Overflow

CWE-681

Incorrect Conversion between Numeric Types

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

CWE-269

Improper Privilege Management

CWE-20

Improper Input Validation

CWE-87

Improper Neutralization of Alternate XSS Syntax

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-18

CWE-18

CWE-385

Covert Timing Channel

CWE-606

Unchecked Input for Loop Condition

CWE-192

Integer Coercion Error

CWE-390

Detection of Error Condition Without Action

CWE-1325

Improperly Controlled Sequential Memory Allocation

CWE-222

Truncation of Security-relevant Information

CWE-131

Incorrect Calculation of Buffer Size

CWE-59

Improper Link Resolution Before File Access ('Link Following')

CWE-304

Missing Critical Step in Authentication

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard