Improper input validation in Oracle Database Server - CVE-2018-11784

 

Improper input validation in Oracle Database Server - CVE-2018-11784

Published: June 4, 2020


Vulnerability identifier: #VU28618
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11784
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper input validation within the WLM (Apache Tomcat) in Oracle Database Server. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.


Affected software

Oracle Database Server
Oracle Secure Global Desktop
Fedora
Oracle Agile Engineering Data Management
MICROS Retail XBRi Loss Prevention
tomcat

How to mitigate CVE-2018-11784

Install updates from vendor's website.

tomcat - addressed in versions 7.0.92-1.el6, 8.5.35-1.fc28, 9.0.13-1.fc29

External References

Related Security Bulletins