Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in diverse Communications producten en systemen.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipuleren van gegevens
- Uitvoer van willekeurige code (Gebruikersrechten)
- Uitvoer van willekeurige code (Administratorrechten)
- Toegang tot gevoelige gegevens
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-122
Heap-based Buffer Overflow
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-20
Improper Input Validation
- CWE-466
Return of Pointer Value Outside of Expected Range
- CWE-606
Unchecked Input for Loop Condition
- CWE-390
Detection of Error Condition Without Action
- CWE-405
Asymmetric Resource Consumption (Amplification)
- CWE-222
Truncation of Security-relevant Information
- CWE-364
Signal Handler Race Condition
- CWE-450
Multiple Interpretations of UI Input
- CWE-130
Improper Handling of Length Parameter Inconsistency
- CWE-772
Missing Release of Resource after Effective Lifetime
- CWE-669
Incorrect Resource Transfer Between Spheres
- CWE-126
Buffer Over-read
- CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data
- CWE-755
Improper Handling of Exceptional Conditions
- CWE-834
Excessive Iteration
- CWE-407
Inefficient Algorithmic Complexity
- CWE-754
Improper Check for Unusual or Exceptional Conditions
- CWE-703
Improper Check or Handling of Exceptional Conditions
- CWE-427
Uncontrolled Search Path Element
- CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- CWE-195
Signed to Unsigned Conversion Error
- CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- CWE-116
Improper Encoding or Escaping of Output
- CWE-345
Insufficient Verification of Data Authenticity
- CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-190
Integer Overflow or Wraparound
- CWE-61
UNIX Symbolic Link (Symlink) Following
- CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-125
Out-of-bounds Read
- CWE-404
Improper Resource Shutdown or Release
- CWE-284
Improper Access Control
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-416
Use After Free
- CWE-401
Missing Release of Memory after Effective Lifetime
- CWE-476
NULL Pointer Dereference
- CWE-459
Incomplete Cleanup
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-248
Uncaught Exception
- CWE-674
Uncontrolled Recursion
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard