Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0022

Published Jan 22, 2025·Last modified Jan 22, 2025
Description
Feiten

Oracle heeft kwetsbaarheden verholpen in Oracle Enterprise Manager

Interpretaties

Een kwaadwillende kan de kwetsbaarheden misbruiken om toegang te verkrijgen tot gevoelige data of een Denial-of-Service te veroorzaken.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-125

Out-of-bounds Read

CWE-400

Uncontrolled Resource Consumption

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-121

Stack-based Buffer Overflow

CWE-20

Improper Input Validation

CWE-178

Improper Handling of Case Sensitivity

CWE-284

Improper Access Control

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard