Improper input validation in Oracle Utilities Framework - CVE-2014-3004
Published: June 4, 2020 / Updated: June 19, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The vulnerability exists due to improper input validation within the Common (Castor) component in Oracle Utilities Framework. A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.
Affected software
IBM Business Process Manager
Netcool Operations Insight
IBM Business Automation Workflow
IBM Tivoli Application Dependency Discovery Manager
Fedora
castor
How to mitigate CVE-2014-3004
castor - update to 1.3.3-1.fc21
Netcool Operations Insight - update to 1.6.8
IBM Business Automation Workflow - addressed in versions 20.0.0.2, 21.0.3, 21.0.3 IF014, 22.0.1, 22.0.1 IF003
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Improper input validation in Oracle Utilities Framework
- Improper input validation in IBM Business Automation Workflow and IBM Business Process Manager
- Improper input validation in IBM Tivoli Application Dependency Discovery Manager
- Multiple vulnerabilities in IBM Netcool Operations Insight
- Fedora 21 update for castor