SB2020071640 - Multiple vulnerabilities in Enterprise Manager Base Platform
Published: July 16, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 5 secuirty vulnerabilities.
1) XML External Entity injection (CVE-ID: CVE-2019-12415)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to insufficient validation of user-supplied XML input when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents. A remote attacker can pass a specially crafted XML code to the affected application and read files from the local filesystem or from internal network resources on the system or initiate requests to external systems.
Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.
2) Improper input validation (CVE-ID: CVE-2020-2982)
The vulnerability allows a remote authenticated user to read and manipulate data.
The vulnerability exists due to improper input validation within the Enterprise Config Management component in Enterprise Manager Base Platform. A remote authenticated user can exploit this vulnerability to read and manipulate data.
3) Improper input validation (CVE-ID: CVE-2019-0227)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Core (Apache Axis) component in Oracle Communications Design Studio. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
4) Improper input validation (CVE-ID: CVE-2018-11776)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient input validation in cases where namespace value isn't set for a result defined in underlying xml configurations and in same time, its upper action(s) configurations have no or wildcard namespace, or when using url tag which doesn’t have value and action set and in same time, its upper action(s) configurations have no or wildcard namespace.
A remote unauthenticated attacker can compromise the affected system.
5) Deserialization of Untrusted Data (CVE-ID: CVE-2020-9546)
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data between serialization gadgets and typing. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note: This vulnerability is related to:
- org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config)
Remediation
Install update from vendor's website.