SB2019011591 - Multiple vulnerabilities in Oracle Application Testing Suite
Published: January 15, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Improper input validation (CVE-ID: CVE-2018-3305)
The vulnerability allows a remote authenticated user to read and manipulate data.
The vulnerability exists due to improper input validation within the Load Testing for Web Apps component in Oracle Application Testing Suite. A remote authenticated user can exploit this vulnerability to read and manipulate data.
2) Improper input validation (CVE-ID: CVE-2018-3304)
The vulnerability allows a remote non-authenticated attacker to manipulate or delete data.
The vulnerability exists due to improper input validation within the Load Testing for Web Apps component in Oracle Application Testing Suite. A remote non-authenticated attacker can exploit this vulnerability to manipulate or delete data.
3) Missing authorization (CVE-ID: CVE-2018-1258)
The vulnerability allows a remote unauthenticated attacker to bypass security restrictions on the target system.The weakness exists due to improper security restrictions when using Spring Security method security. A remote attacker can submit a specially crafted request, bypass authorization restrictions and gain unauthorized access to certain methods that should be restricted.
Remediation
Install update from vendor's website.