Improper input validation in Oracle Database Server - CVE-2018-11784
Published: June 4, 2020
Vulnerability identifier: #VU28618
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11784
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to manipulate data.
The vulnerability exists due to improper input validation within the WLM (Apache Tomcat) in Oracle Database Server. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.
Affected software
Oracle Database Server
Oracle Secure Global Desktop
Fedora
Oracle Agile Engineering Data Management
MICROS Retail XBRi Loss Prevention
tomcat
Oracle Secure Global Desktop
Fedora
Oracle Agile Engineering Data Management
MICROS Retail XBRi Loss Prevention
tomcat
How to mitigate CVE-2018-11784
Install updates from vendor's website.
tomcat - addressed in versions 7.0.92-1.el6, 8.5.35-1.fc28, 9.0.13-1.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Database Server
- Fedora 28 update for tomcat
- Fedora EPEL 6 update for tomcat
- Fedora 29 update for tomcat
- Multiple vulnerabilities in MICROS Retail XBRi Loss Prevention
- Multiple vulnerabilities in Oracle Agile Engineering Data Management
- Multiple vulnerabilities in Oracle Secure Global Desktop