Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2025-0330

Published Oct 23, 2025·Last modified Oct 23, 2025
Description
Feiten

Oracle heeft meerdere kwetsbaarheden verholpen in zijn Communications producten, waaronder de Unified Assurance en Cloud Native Core.

Interpretaties

De kwetsbaarheden in de Oracle Communications producten stellen kwaadwillenden in staat om ongeautoriseerde toegang te verkrijgen, wat kan leiden tot gedeeltelijke of volledige Denial-of-Service (DoS) aanvallen. Specifiek kunnen aanvallers met netwerktoegang de systemen compromitteren, wat resulteert in ongeautoriseerde toegang tot gevoelige gegevens. De CVSS-scores van deze kwetsbaarheden variëren van 3.1 tot 9.8, wat wijst op een breed scala aan risico's, van beperkte tot ernstige impact op de vertrouwelijkheid, integriteit en beschikbaarheid van de systemen.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden in zijn Communications producten te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-20

Improper Input Validation

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-23

Relative Path Traversal

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

CWE-121

Stack-based Buffer Overflow

CWE-122

Heap-based Buffer Overflow

CWE-124

Buffer Underwrite ('Buffer Underflow')

CWE-125

Out-of-bounds Read

CWE-129

Improper Validation of Array Index

CWE-130

Improper Handling of Length Parameter Inconsistency

CWE-147

Improper Neutralization of Input Terminators

CWE-190

Integer Overflow or Wraparound

CWE-197

Numeric Truncation Error

CWE-241

Improper Handling of Unexpected Data Type

CWE-252

Unchecked Return Value

CWE-253

Incorrect Check of Function Return Value

CWE-284

Improper Access Control

CWE-287

Improper Authentication

CWE-290

Authentication Bypass by Spoofing

CWE-328

Use of Weak Hash

CWE-385

Covert Timing Channel

CWE-390

Detection of Error Condition Without Action

CWE-400

Uncontrolled Resource Consumption

CWE-404

Improper Resource Shutdown or Release

CWE-407

Inefficient Algorithmic Complexity

CWE-409

Improper Handling of Highly Compressed Data (Data Amplification)

CWE-415

Double Free

CWE-416

Use After Free

CWE-426

Untrusted Search Path

CWE-440

Expected Behavior Violation

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

CWE-476

NULL Pointer Dereference

CWE-674

Uncontrolled Recursion

CWE-697

Incorrect Comparison

CWE-770

Allocation of Resources Without Limits or Throttling

CWE-787

Out-of-bounds Write

CWE-789

Memory Allocation with Excessive Size Value

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

CWE-843

Access of Resource Using Incompatible Type ('Type Confusion')

CWE-918

Server-Side Request Forgery (SSRF)

CWE-937

CWE-937

CWE-1035

CWE-1035

CWE-1284

Improper Validation of Specified Quantity in Input

CWE-1333

Inefficient Regular Expression Complexity

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard