Improper input validation - CVE-2018-1000180

 

Improper input validation - CVE-2018-1000180

Published: April 21, 2020


Vulnerability identifier: #VU27043
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2018-1000180
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Software vendor:
Vulnerable software:

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation within the IDIH Visualization (Bouncy Castle Java Library) component in Oracle Communications Diameter Signaling Router (DSR). A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.


How to mitigate CVE-2018-1000180

Install updates from vendor's website.

Sources