Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in Oracle Analytics producten, zoals Business Intelligence, Analytics Desktop en BI Publisher.
- Interpretaties
Een kwaadwillende kan de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, of zich toegang te verschaffen tot gevoelige gegevens.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-416
Use After Free
- CWE-476
NULL Pointer Dereference
- CWE-400
Uncontrolled Resource Consumption
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-502
Deserialization of Untrusted Data
- CWE-248
Uncaught Exception
- CWE-674
Uncontrolled Recursion
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-789
Memory Allocation with Excessive Size Value
- CWE-20
Improper Input Validation
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-1395
Dependency on Vulnerable Third-Party Component
- CWE-670
Always-Incorrect Control Flow Implementation
- CWE-399
CWE-399
- CWE-326
Inadequate Encryption Strength
- CWE-669
Incorrect Resource Transfer Between Spheres
- CWE-776
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')
- CWE-834
Excessive Iteration
- CWE-311
Missing Encryption of Sensitive Data
- CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- CWE-125
Out-of-bounds Read
- CWE-404
Improper Resource Shutdown or Release
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-1333
Inefficient Regular Expression Complexity
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard