Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2026-0021

Published Jan 21, 2026·Last modified Jan 21, 2026
Description
Feiten

Oracle heeft kwetsbaarheden verholpen in Oracle Database Server producten.

Interpretaties

De kwetsbaarheden in Oracle Database Server stellen niet-geauthenticeerde aanvallers in staat om de integriteit en vertrouwelijkheid van gegevens te compromitteren. Dit kan leiden tot ongeautoriseerde toegang tot gevoelige data en zelfs een mogelijke overname van de SQLcl-component.

Oplossingen

Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-20

Improper Input Validation

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-93

Improper Neutralization of CRLF Sequences ('CRLF Injection')

CWE-150

Improper Neutralization of Escape, Meta, or Control Sequences

CWE-201

Insertion of Sensitive Information Into Sent Data

CWE-295

Improper Certificate Validation

CWE-297

Improper Validation of Certificate with Host Mismatch

CWE-326

Inadequate Encryption Strength

CWE-347

Improper Verification of Cryptographic Signature

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

CWE-404

Improper Resource Shutdown or Release

CWE-457

Use of Uninitialized Variable

CWE-502

Deserialization of Untrusted Data

CWE-674

Uncontrolled Recursion

CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')

CWE-862

Missing Authorization

CWE-908

Use of Uninitialized Resource

CWE-937

CWE-937

CWE-1035

CWE-1035

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard