Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0021

Published Jan 22, 2025·Last modified Jan 22, 2025
Description
Feiten

Oracle heeft meerdere kwetsbaarheden verholpen in zijn Communicatieproducten, waaronder Oracle Communications Unified Assurance, Oracle Communications Cloud Native Core Network Function en Oracle Communications Order and Service Management.

Interpretaties

De kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om Denial of Service (DoS) aanvallen uit te voeren of om ongeautoriseerde toegang tot gevoelige gegevens te verkrijgen. Specifieke versies, zoals 24.2.0 en 24.3.0 van de Cloud Native Core Network Function, zijn bijzonder kwetsbaar. Kwaadwillenden kunnen deze kwetsbaarheden misbruiken door speciaal geprepareerde HTTP-verzoeken te sturen naar het kwetsbare systeem.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-1395

Dependency on Vulnerable Third-Party Component

CWE-670

Always-Incorrect Control Flow Implementation

CWE-405

Asymmetric Resource Consumption (Amplification)

CWE-35

Path Traversal: '.../...//'

CWE-466

Return of Pointer Value Outside of Expected Range

CWE-338

Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)

CWE-676

Use of Potentially Dangerous Function

CWE-606

Unchecked Input for Loop Condition

CWE-450

Multiple Interpretations of UI Input

CWE-131

Incorrect Calculation of Buffer Size

CWE-328

Use of Weak Hash

CWE-130

Improper Handling of Length Parameter Inconsistency

CWE-669

Incorrect Resource Transfer Between Spheres

CWE-1220

Insufficient Granularity of Access Control

CWE-201

Insertion of Sensitive Information Into Sent Data

CWE-349

Acceptance of Extraneous Untrusted Data With Trusted Data

CWE-755

Improper Handling of Exceptional Conditions

CWE-347

Improper Verification of Cryptographic Signature

CWE-834

Excessive Iteration

CWE-178

Improper Handling of Case Sensitivity

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-440

Expected Behavior Violation

CWE-415

Double Free

CWE-311

Missing Encryption of Sensitive Data

CWE-924

Improper Enforcement of Message Integrity During Transmission in a Communication Channel

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-703

Improper Check or Handling of Exceptional Conditions

CWE-617

Reachable Assertion

CWE-427

Uncontrolled Search Path Element

CWE-836

Use of Password Hash Instead of Password for Authentication

CWE-680

Integer Overflow to Buffer Overflow

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

CWE-23

Relative Path Traversal

CWE-116

Improper Encoding or Escaping of Output

CWE-345

Insufficient Verification of Data Authenticity

CWE-203

Observable Discrepancy

CWE-354

Improper Validation of Integrity Check Value

CWE-325

Missing Cryptographic Step

CWE-190

Integer Overflow or Wraparound

CWE-451

User Interface (UI) Misrepresentation of Critical Information

CWE-61

UNIX Symbolic Link (Symlink) Following

CWE-552

Files or Directories Accessible to External Parties

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-798

Use of Hard-coded Credentials

CWE-434

Unrestricted Upload of File with Dangerous Type

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-404

Improper Resource Shutdown or Release

CWE-284

Improper Access Control

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-1333

Inefficient Regular Expression Complexity

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-416

Use After Free

CWE-476

NULL Pointer Dereference

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-502

Deserialization of Untrusted Data

CWE-248

Uncaught Exception

CWE-674

Uncontrolled Recursion

CWE-863

Incorrect Authorization

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-611

Improper Restriction of XML External Entity Reference

CWE-787

Out-of-bounds Write

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-122

Heap-based Buffer Overflow

CWE-121

Stack-based Buffer Overflow

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

CWE-269

Improper Privilege Management

CWE-20

Improper Input Validation

CWE-209

Generation of Error Message Containing Sensitive Information

CWE-276

Incorrect Default Permissions

CWE-294

Authentication Bypass by Capture-replay

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard