Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft meerdere kwetsbaarheden verholpen in Oracle PeopleSoft, specifiek in de versies 8.60, 8.61 en 9.2.
- Interpretaties
De kwetsbaarheden in Oracle PeopleSoft stellen geauthenticeerde kwaadwillenden in staat om via HTTP-netwerktoegang ongeautoriseerde toegang te krijgen tot specifieke gegevens, wat kan leiden tot ongeautoriseerde gegevensmanipulatie en -toegang. Kwaadwillenden kunnen ook een Denial-of-Service veroorzaken. Hiervoor heeft de kwaadwillende geen voorafgaande authenticatie nodig.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden in PeopleSoft te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-670
Always-Incorrect Control Flow Implementation
- CWE-1395
Dependency on Vulnerable Third-Party Component
- CWE-669
Incorrect Resource Transfer Between Spheres
- CWE-126
Buffer Over-read
- CWE-125
Out-of-bounds Read
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard