Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in Oracle Communications producten.
- Interpretaties
De kwetsbaarheden stellen aanvallers in staat om ongeautoriseerde toegang te krijgen tot het systeem, wat kan leiden tot gegevensmanipulatie en gedeeltelijke denial-of-service. De aanvallers kunnen deze kwetsbaarheden misbruiken via HTTP-verzoeken, wat mogelijk resulteert in een significante impact op de beschikbaarheid en integriteit van de gegevens.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-863
Incorrect Authorization
- CWE-937
CWE-937
- CWE-1035
CWE-1035
- CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
- CWE-20
Improper Input Validation
- CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-116
Improper Encoding or Escaping of Output
- CWE-121
Stack-based Buffer Overflow
- CWE-122
Heap-based Buffer Overflow
- CWE-123
Write-what-where Condition
- CWE-125
Out-of-bounds Read
- CWE-126
Buffer Over-read
- CWE-201
Insertion of Sensitive Information Into Sent Data
- CWE-209
Generation of Error Message Containing Sensitive Information
- CWE-252
Unchecked Return Value
- CWE-284
Improper Access Control
- CWE-285
Improper Authorization
- CWE-295
Improper Certificate Validation
- CWE-297
Improper Validation of Certificate with Host Mismatch
- CWE-393
Return of Wrong Status Code
- CWE-400
Uncontrolled Resource Consumption
- CWE-404
Improper Resource Shutdown or Release
- CWE-407
Inefficient Algorithmic Complexity
- CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
- CWE-415
Double Free
- CWE-416
Use After Free
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-674
Uncontrolled Recursion
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-787
Out-of-bounds Write
- CWE-789
Memory Allocation with Excessive Size Value
- CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard