Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
- Feiten
Oracle heeft kwetsbaarheden verholpen in verschillende producten, waaronder Oracle HTTP Server, Oracle WebLogic Server, en Oracle Fusion Middleware.
- Interpretaties
De kwetsbaarheden in de Oracle producten stellen ongeauthenticeerde aanvallers in staat om toegang te krijgen tot gevoelige gegevens, Denial-of-Service (DoS) aanvallen uit te voeren, en de integriteit van systemen te compromitteren. Specifieke kwetsbaarheden omvatten onjuist beheer van HTTP-headers, ongecontroleerde recursie, en onvoldoende bufferbeperkingen, wat kan leiden tot systeemcrashes en gegevensverlies.
- Oplossingen
Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie.
- Kans
medium
- Schade
high
- CWE-20
Improper Input Validation
- CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-94
Improper Control of Generation of Code ('Code Injection')
- CWE-113
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
- CWE-117
Improper Output Neutralization for Logs
- CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-122
Heap-based Buffer Overflow
- CWE-125
Out-of-bounds Read
- CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
- CWE-209
Generation of Error Message Containing Sensitive Information
- CWE-252
Unchecked Return Value
- CWE-284
Improper Access Control
- CWE-285
Improper Authorization
- CWE-289
Authentication Bypass by Alternate Name
- CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
- CWE-400
Uncontrolled Resource Consumption
- CWE-404
Improper Resource Shutdown or Release
- CWE-457
Use of Uninitialized Variable
- CWE-476
NULL Pointer Dereference
- CWE-611
Improper Restriction of XML External Entity Reference
- CWE-674
Uncontrolled Recursion
- CWE-770
Allocation of Resources Without Limits or Throttling
- CWE-787
Out-of-bounds Write
- CWE-827
Improper Control of Document Type Definition
- CWE-843
Access of Resource Using Incompatible Type ('Type Confusion')
- CWE-863
Incorrect Authorization
- CWE-918
Server-Side Request Forgery (SSRF)
- CWE-937
CWE-937
- CWE-1035
CWE-1035
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard