Improper input validation in Oracle Endeca Information Discovery Integrator - CVE-2019-10247

 

Improper input validation in Oracle Endeca Information Discovery Integrator - CVE-2019-10247

Published: February 7, 2020


Vulnerability identifier: #VU25067
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10247
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Integrator Acquistion System (Eclipse Jetty) component in Oracle Endeca Information Discovery Integrator. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.


Affected software

Oracle Endeca Information Discovery Integrator
Oracle Hospitality Guest Access
Oracle Communications Element Manager
Oracle Communications Session Route Manager
Oracle Unified Directory
Traffix SDC
Oracle FLEXCUBE Core Banking
IBM Cognos Command Center
Oracle Communications Services Gatekeeper
AMQ Broker
BIG-IQ Centralized Management
Oracle Retail Xstore Point of Service
Oracle FLEXCUBE Private Banking
Oracle Data Integrator
Oracle Communications Session Report Manager
Oracle Communications Analytics
Enterprise Manager Base Platform
IBM Process Mining
IBM Cloud Application Performance Management (APM)
IBM Spectrum Protect Storage Agent
IBM Security Verify Governance
jetty9 (Debian package)
Opensuse
Oracle AutoVue
Operational Decision Manager
watsonx.data

How to mitigate CVE-2019-10247

Install updates from vendor's website.

AMQ Broker - addressed in versions 7.4.3, 7.6
jetty9 (Debian package) - update to 9.4.16-0+deb10u1
IBM Process Mining - update to 1.12.0.4
watsonx.data - update to 2.0.1
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.15
IBM Spectrum Protect Storage Agent - update to 8.1.19
Operational Decision Manager - addressed in versions 8.10.5.2 Interim fix 1, 8.11.0.1 Interim fix 30, 8.11.1 Interim fix 24, 8.12.0.1 Interim fix 5
IBM Security Verify Governance - update to 10.0.1.0.3
IBM Cognos Command Center - update to 10.2.4 Fix Pack 1 IF17

External References

Related Security Bulletins