Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in Analytics producten.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service
- Manipuleren van data
- Uitvoer van willekeurige code (Gebruikersrechten)
- Uitvoer van willekeurige code (Administratorrechten)
- Toegang tot gevoelige gegevens
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-606
Unchecked Input for Loop Condition
- CWE-754
Improper Check for Unusual or Exceptional Conditions
- CWE-345
Insufficient Verification of Data Authenticity
- CWE-325
Missing Cryptographic Step
- CWE-404
Improper Resource Shutdown or Release
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-1333
Inefficient Regular Expression Complexity
- CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CWE-476
NULL Pointer Dereference
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-787
Out-of-bounds Write
- CWE-122
Heap-based Buffer Overflow
- CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard