Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in Oracle Database Server producten.
- Interpretaties
De kwetsbaarheden in Oracle Database Server stellen niet-geauthenticeerde aanvallers in staat om de integriteit en vertrouwelijkheid van gegevens te compromitteren. Dit kan leiden tot ongeautoriseerde toegang tot gevoelige data en zelfs een mogelijke overname van de SQLcl-component.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-20
Improper Input Validation
- CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
- CWE-93
Improper Neutralization of CRLF Sequences ('CRLF Injection')
- CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
- CWE-201
Insertion of Sensitive Information Into Sent Data
- CWE-295
Improper Certificate Validation
- CWE-297
Improper Validation of Certificate with Host Mismatch
- CWE-326
Inadequate Encryption Strength
- CWE-347
Improper Verification of Cryptographic Signature
- CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-404
Improper Resource Shutdown or Release
- CWE-457
Use of Uninitialized Variable
- CWE-502
Deserialization of Untrusted Data
- CWE-674
Uncontrolled Recursion
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
- CWE-862
Missing Authorization
- CWE-908
Use of Uninitialized Resource
- CWE-937
CWE-937
- CWE-1035
CWE-1035
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard