Risk | Critical |
Patch available | YES |
Number of vulnerabilities | 12 |
CVE-ID | CVE-2021-22096 CVE-2021-20289 CVE-2021-22569 CVE-2020-14340 CVE-2021-2471 CVE-2021-30129 CVE-2021-44832 CVE-2021-3712 CVE-2020-25638 CVE-2020-36518 CVE-2022-22965 CVE-2022-23221 |
CWE-ID | CWE-20 CWE-200 CWE-399 CWE-119 CWE-94 CWE-125 CWE-89 CWE-787 CWE-502 |
Exploitation vector | Network |
Public exploit |
Public exploit code for vulnerability #3 is available. Public exploit code for vulnerability #5 is available. Vulnerability #11 is being exploited in the wild. |
Vulnerable software Subscribe |
Oracle Communications Cloud Native Core Console Server applications / DLP, anti-spam, sniffers |
Vendor | Oracle |
Security Bulletin
This security bulletin contains information about 12 vulnerabilities.
EUVDB-ID: #VU61720
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-22096
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to modify existing log records.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the application and inject arbitrary records into log files.
Install update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU56965
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2021-20289
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application when RESTEasy cannot convert one of the request URI path or query values to the matching JAX-RS resource method's parameter value. A remote attacker can obtain endpoint class and method names.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU60181
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-22569
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application. protobuf-java allowes the interleaving of
com.google.protobuf.UnknownFieldSet fields in such a way that would be
processed out of order. A small malicious payload can occupy the parser
for several minutes by creating large numbers of short-lived objects
that cause frequent, repeated pauses. A remote attacker can trick the victim into passing specially crafted data to the application and perform a denial of service attack.
Install update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU60097
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-14340
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the UDR (XNIO) component in Oracle Communications Cloud Native Core Unified Data Repository. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU57510
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-2471
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote privileged user to read data or crash the application.
The vulnerability exists due to improper input validation within the Connector/J component in MySQL Connectors. A remote privileged user can exploit this vulnerability to read data or crash the application.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU56931
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-30129
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the sshd-core of Apache Mina SSHD. A remote attacker can send specially crafted requests to the server, trigger buffer overflow and perform a denial of service (DoS) attack.
Install update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU59098
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-44832
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote user to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote user with permission to modify the logging configuration file can construct a malicious configuration using a JDBC Appender with a data source referencing a JNDI URI which can execute remote code.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU56064
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2021-3712
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when processing ASN.1 strings related to a confusion with NULL termination of strings in array. A remote attacker can pass specially crafted data to the application to trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service (DoS) attack.
Install update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU48543
Risk: High
CVSSv3.1:
CVE-ID: CVE-2020-25638
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data when "hibernate.use_sql_comments" is configured to true. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.
Successful exploitation of this vulnerability may allow a remote attacker to read, delete, modify data in database and gain complete control over the affected application.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU61799
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-36518
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing untrusted input. A remote attacker can trigger out-of-bounds write and cause a denial of service condition on the target system.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU61756
Risk: Critical
CVSSv3.1:
CVE-ID: CVE-2022-22965
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper input validation. A remote attacker can send a specially crafted HTTP request to the affected application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Note, the vulnerability is being actively exploited in the wild.
This vulnerability was dubbed "Spring4Shell".
Install update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0 - 22.1.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU61938
Risk: High
CVSSv3.1:
CVE-ID: CVE-2022-23221
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data within jdbc:h2:mem. A remote attacker can pass specially crafted JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsOracle Communications Cloud Native Core Console: 1.9.0
Fixed software versionsCPE2.3 External links
http://www.oracle.com/security-alerts/cpuapr2022.html?936691
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?