Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in verschillende producten, waaronder Oracle Banking Liquidity Management, Oracle Financial Services Model Management en Oracle FLEXCUBE.
- Interpretaties
De kwetsbaarheden in de Oracle producten stellen ongeauthenticeerde aanvallers in staat om toegang te krijgen tot gevoelige gegevens en Denial-of-Service (DoS) aan te richten. Dit kan leiden tot vertrouwelijkheids- en integriteitsrisico's. Specifieke kwetsbaarheden omvatten onjuist beheer van verbindingen en onvoldoende invoervalidatie wat kan resulteren in systeemcompromittering en serviceonderbrekingen.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-125
Out-of-bounds Read
- CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
- CWE-284
Improper Access Control
- CWE-285
Improper Authorization
- CWE-287
Improper Authentication
- CWE-289
Authentication Bypass by Alternate Name
- CWE-400
Uncontrolled Resource Consumption
- CWE-404
Improper Resource Shutdown or Release
- CWE-521
Weak Password Requirements
- CWE-674
Uncontrolled Recursion
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-787
Out-of-bounds Write
- CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
- CWE-863
Incorrect Authorization
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-937
CWE-937
- CWE-1035
CWE-1035
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard