Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in JD Edwards EnterpriseOne Tools (specifiek voor versies prior tot 9.2.9.2).
- Interpretaties
De kwetsbaarheden in Oracle JD Edwards EnterpriseOne Tools stellen ongeauthenticeerde kwaadwillenden in staat om het systeem te compromitteren via HTTP-verzoeken. Dit kan leiden tot ongeautoriseerde toegang tot kritieke gegevens en gegevenswijzigingen.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-222
Truncation of Security-relevant Information
- CWE-328
Use of Weak Hash
- CWE-126
Buffer Over-read
- CWE-379
Creation of Temporary File in Directory with Insecure Permissions
- CWE-440
Expected Behavior Violation
- CWE-1286
Improper Validation of Syntactic Correctness of Input
- CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
- CWE-354
Improper Validation of Integrity Check Value
- CWE-552
Files or Directories Accessible to External Parties
- CWE-757
Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade')
- CWE-327
Use of a Broken or Risky Cryptographic Algorithm
- CWE-400
Uncontrolled Resource Consumption
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-787
Out-of-bounds Write
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-606
Unchecked Input for Loop Condition
- CWE-1322
Use of Blocking Code in Single-threaded, Non-blocking Context
- CWE-280
Improper Handling of Insufficient Permissions or Privileges
- CWE-754
Improper Check for Unusual or Exceptional Conditions
- CWE-325
Missing Cryptographic Step
- CWE-125
Out-of-bounds Read
- CWE-404
Improper Resource Shutdown or Release
- CWE-476
NULL Pointer Dereference
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
- CWE-502
Deserialization of Untrusted Data
- CWE-122
Heap-based Buffer Overflow
- CWE-20
Improper Input Validation
- CWE-276
Incorrect Default Permissions
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard