Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft meerdere kwetsbaarheden verholpen in verschillende producten, waaronder de Utilities Application Framework, WebLogic Server, en Fusion Middleware.
- Interpretaties
De kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om toegang te krijgen tot kritieke gegevens, Denial-of-Service (DoS) te veroorzaken, en in sommige gevallen zelfs volledige controle over systemen te verkrijgen. Kwaadwillenden kunnen deze kwetsbaarheden misbruiken door speciaal vervaardigde verzoeken te sturen of door gebruik te maken van onveilige configuraties in de getroffen producten.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
- CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
- CWE-754
Improper Check for Unusual or Exceptional Conditions
- CWE-125
Out-of-bounds Read
- CWE-404
Improper Resource Shutdown or Release
- CWE-829
Inclusion of Functionality from Untrusted Control Sphere
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-400
Uncontrolled Resource Consumption
- CWE-502
Deserialization of Untrusted Data
- CWE-674
Uncontrolled Recursion
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-787
Out-of-bounds Write
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-121
Stack-based Buffer Overflow
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-20
Improper Input Validation
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard