Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0127

Published Apr 16, 2025·Last modified Apr 16, 2025
Description
Feiten

Oracle heeft kwetsbaarheden verholpen in verschillende Financial Services producten

Interpretaties

De kwetsbaarheden stellen niet-geauthenticeerde kwaadwillenden in staat om via HTTP toegang te krijgen tot kritieke gegevens, wat kan leiden tot ongeautoriseerde gegevenstoegang en andere beveiligingsrisico's. Kwaadwillenden kunnen ook gebruik maken van misconfiguraties en kwetsbaarheden in de software om privilege-escalatie, denial-of-service en remote code execution uit te voeren.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-670

Always-Incorrect Control Flow Implementation

CWE-676

Use of Potentially Dangerous Function

CWE-921

Storage of Sensitive Data in a Mechanism without Access Control

CWE-922

Insecure Storage of Sensitive Information

CWE-669

Incorrect Resource Transfer Between Spheres

CWE-178

Improper Handling of Case Sensitivity

CWE-303

Incorrect Implementation of Authentication Algorithm

CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

CWE-680

Integer Overflow to Buffer Overflow

CWE-639

Authorization Bypass Through User-Controlled Key

CWE-404

Improper Resource Shutdown or Release

CWE-284

Improper Access Control

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-400

Uncontrolled Resource Consumption

CWE-502

Deserialization of Untrusted Data

CWE-674

Uncontrolled Recursion

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-611

Improper Restriction of XML External Entity Reference

CWE-121

Stack-based Buffer Overflow

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-20

Improper Input Validation

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard