Improper input validation in Application Performance Management - CVE-2019-3740

 

Improper input validation in Application Performance Management - CVE-2019-3740

Published: October 30, 2020


Vulnerability identifier: #VU48048
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3740
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Comp Management and Life Cycle Management (RSA BSAFE Crypto-J) component in Application Performance Management (APM). A remote non-authenticated attacker can exploit this vulnerability to gain access to sensitive information.


Affected software

Application Performance Management
Oracle Communications Network Integrity
Oracle Communications Unified Inventory Management
Oracle StorageTek ACSLS
Oracle Global Lifecycle Management OPatch
Oracle WebLogic Server
Oracle Retail Predictive Application Server
Oracle Database Server
Oracle GoldenGate
Oracle Retail Service Backbone
Oracle Retail Xstore Point of Service
Oracle Retail Integration Bus
Oracle Retail Assortment Planning

How to mitigate CVE-2019-3740

Install updates from vendor's website.

Oracle Global Lifecycle Management OPatch - update to 12.2.0.1.22

External References

Related Security Bulletins