Improper input validation in Oracle Retail Order Broker Cloud Service - CVE-2020-13954
Published: January 20, 2021
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The vulnerability exists due to improper input validation within the Supplier Direct Fulfillment (Apache CXF) component in Oracle Retail Order Broker Cloud Service. A remote non-authenticated attacker can exploit this vulnerability to read and manipulate data.
Affected software
IBM Intelligent Operations Center
InfoSphere Master Data Management
IBM Qradar SIEM
Oracle Communications Instant Messaging Server
Voice Gateway
IBM Security Guardium
Oracle WebCenter Sites
How to mitigate CVE-2020-13954
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 10, 7.4.3 Fix Pack 3, 7.4.3 Fix Pack 4
Voice Gateway - addressed in versions 1.0.8.2, 1.0.8.6
InfoSphere Master Data Management - update to 11.6.0.12
External References
Related Security Bulletins
- Improper input validation in Oracle Retail Order Broker Cloud Service
- Multiple vulnerabilities in Oracle Communications Messaging Server
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Security Guardium
- Improper input validation in IBM InfoSphere Master Data Management
- Multiple vulnerabilities in IBM Voice Gateway
- Improper input validation in Oracle WebCenter Sites
- Multiple vulnerabilities in IBM Intelligent Operations Center (IOC)