Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in Oracle Financial Services componenten.
- Interpretaties
De kwetsbaarheden stellen ongeauthenticeerde aanvallers in staat om ongeautoriseerde toegang te krijgen tot gevoelige gegevens via HTTP. Dit kan leiden tot ongeoorloofde toegang en wijzigingen van kritieke data, met een CVSS-score van 9.8 die de significante impact op de vertrouwelijkheid benadrukt. Daarnaast zijn er kwetsbaarheden die kunnen leiden tot denial-of-service (DoS) aanvallen, wat de beschikbaarheid van het systeem in gevaar kan brengen.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-20
Improper Input Validation
- CWE-23
Relative Path Traversal
- CWE-125
Out-of-bounds Read
- CWE-197
Numeric Truncation Error
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-284
Improper Access Control
- CWE-285
Improper Authorization
- CWE-306
Missing Authentication for Critical Function
- CWE-400
Uncontrolled Resource Consumption
- CWE-404
Improper Resource Shutdown or Release
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-674
Uncontrolled Recursion
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-862
Missing Authorization
- CWE-863
Incorrect Authorization
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-937
CWE-937
- CWE-1035
CWE-1035
- CWE-1284
Improper Validation of Specified Quantity in Input
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard