Improper input validation - CVE-2018-1000180

 

Improper input validation - CVE-2018-1000180

Published: April 21, 2020


Vulnerability identifier: #VU27043
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000180
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation within the IDIH Visualization (Bouncy Castle Java Library) component in Oracle Communications Diameter Signaling Router (DSR). A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.


Affected software

Oracle Retail Convenience and Fuel POS Software
Oracle Enterprise Repository
Oracle Business Process Management Suite
Oracle Communications Convergence
Oracle Communications Diameter Signaling Router (DSR)
Dell Secure Connect Gateway
Oracle Communications WebRTC Session Controller
IBM Observability with Instana
Oracle WebCenter Portal
Oracle WebLogic Server
Oracle Communications Converged Application Server
Fuse
Oracle Data Integrator
CloudLink
Oracle Enterprise Manager for Fusion Middleware
Fedora
Opensuse
bouncycastle
IBM Sterling File Gateway

How to mitigate CVE-2018-1000180

Install updates from vendor's website.

bouncycastle - addressed in versions 1.59-1.fc27, 1.59-1.fc28
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling File Gateway - addressed in versions 6.0.3.7, 6.1.0.5, 6.1.1.2, 6.1.2.0
Oracle Communications Converged Application Server - update to 7.0.0.1
Fuse - update to 7.1.0
Oracle Communications WebRTC Session Controller - update to 7.2
CloudLink - update to 8.0-3.10.5.1
IBM Observability with Instana - update to 269

External References

Related Security Bulletins