Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0124

Published Apr 16, 2025·Last modified Apr 16, 2025
Description
Feiten

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle Communications producten, waaronder de Cloud Native Core en Policy Management.

Interpretaties

De kwetsbaarheden in Oracle Communications producten stellen ongeauthenticeerde aanvallers in staat om ongeautoriseerde toegang te verkrijgen tot gevoelige gegevens en kunnen leiden tot Denial-of-Service (DoS) aanvallen. Specifieke versies van de Cloud Native Core, zoals de Binding Support Function en Network Repository Function, zijn getroffen, met CVSS-scores die variëren van 4.3 tot 9.8, wat wijst op significante risico's voor de beschikbaarheid en vertrouwelijkheid van de systemen.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-44

Path Equivalence: 'file.name' (Internal Dot)

CWE-706

Use of Incorrectly-Resolved Name or Reference

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CWE-1321

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

CWE-502

Deserialization of Untrusted Data

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-121

Stack-based Buffer Overflow

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-1395

Dependency on Vulnerable Third-Party Component

CWE-653

Improper Isolation or Compartmentalization

CWE-670

Always-Incorrect Control Flow Implementation

CWE-676

Use of Potentially Dangerous Function

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine

CWE-392

Missing Report of Error Condition

CWE-772

Missing Release of Resource after Effective Lifetime

CWE-208

Observable Timing Discrepancy

CWE-669

Incorrect Resource Transfer Between Spheres

CWE-349

Acceptance of Extraneous Untrusted Data With Trusted Data

CWE-834

Excessive Iteration

CWE-303

Incorrect Implementation of Authentication Algorithm

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

CWE-1286

Improper Validation of Syntactic Correctness of Input

CWE-754

Improper Check for Unusual or Exceptional Conditions

CWE-680

Integer Overflow to Buffer Overflow

CWE-345

Insufficient Verification of Data Authenticity

CWE-369

Divide By Zero

CWE-552

Files or Directories Accessible to External Parties

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-404

Improper Resource Shutdown or Release

CWE-862

Missing Authorization

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-1333

Inefficient Regular Expression Complexity

CWE-295

Improper Certificate Validation

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-327

Use of a Broken or Risky Cryptographic Algorithm

CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-674

Uncontrolled Recursion

CWE-611

Improper Restriction of XML External Entity Reference

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-269

Improper Privilege Management

CWE-20

Improper Input Validation

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard