Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft meerdere kwetsbaarheden verholpen in zijn Communications producten, waaronder de Unified Assurance en Cloud Native Core.
- Interpretaties
De kwetsbaarheden in de Oracle Communications producten stellen kwaadwillenden in staat om ongeautoriseerde toegang te verkrijgen, wat kan leiden tot gedeeltelijke of volledige Denial-of-Service (DoS) aanvallen. Specifiek kunnen aanvallers met netwerktoegang de systemen compromitteren, wat resulteert in ongeautoriseerde toegang tot gevoelige gegevens. De CVSS-scores van deze kwetsbaarheden variëren van 3.1 tot 9.8, wat wijst op een breed scala aan risico's, van beperkte tot ernstige impact op de vertrouwelijkheid, integriteit en beschikbaarheid van de systemen.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden in zijn Communications producten te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-20
Improper Input Validation
- CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-23
Relative Path Traversal
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
- CWE-121
Stack-based Buffer Overflow
- CWE-122
Heap-based Buffer Overflow
- CWE-124
Buffer Underwrite ('Buffer Underflow')
- CWE-125
Out-of-bounds Read
- CWE-129
Improper Validation of Array Index
- CWE-130
Improper Handling of Length Parameter Inconsistency
- CWE-147
Improper Neutralization of Input Terminators
- CWE-190
Integer Overflow or Wraparound
- CWE-197
Numeric Truncation Error
- CWE-241
Improper Handling of Unexpected Data Type
- CWE-252
Unchecked Return Value
- CWE-253
Incorrect Check of Function Return Value
- CWE-284
Improper Access Control
- CWE-287
Improper Authentication
- CWE-290
Authentication Bypass by Spoofing
- CWE-328
Use of Weak Hash
- CWE-385
Covert Timing Channel
- CWE-390
Detection of Error Condition Without Action
- CWE-400
Uncontrolled Resource Consumption
- CWE-404
Improper Resource Shutdown or Release
- CWE-407
Inefficient Algorithmic Complexity
- CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
- CWE-415
Double Free
- CWE-416
Use After Free
- CWE-426
Untrusted Search Path
- CWE-440
Expected Behavior Violation
- CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
- CWE-476
NULL Pointer Dereference
- CWE-674
Uncontrolled Recursion
- CWE-697
Incorrect Comparison
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-787
Out-of-bounds Write
- CWE-789
Memory Allocation with Excessive Size Value
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-937
CWE-937
- CWE-1035
CWE-1035
- CWE-1284
Improper Validation of Specified Quantity in Input
- CWE-1333
Inefficient Regular Expression Complexity
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard