Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in Financial Services Applications.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Cross-Site-Scripting (XSS)
- Denial-of-Service (DoS)
- Manipuleren van data
- Uitvoer van willekeurige code (Gebruikersrechten)
- Uitvoer van willekeurige code (Administratorrechten)
- Toegang tot gevoelige gegevens
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-1325
Improperly Controlled Sequential Memory Allocation
- CWE-1188
Initialization of a Resource with an Insecure Default
- CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
- CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- CWE-345
Insufficient Verification of Data Authenticity
- CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-404
Improper Resource Shutdown or Release
- CWE-306
Missing Authentication for Critical Function
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-416
Use After Free
- CWE-295
Improper Certificate Validation
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-20
Improper Input Validation
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard