Improper input validation in Oracle Communications Cloud Native Core Policy - CVE-2021-22119
Published: January 27, 2022 / Updated: November 10, 2022
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the Policy (Spring Security) component in Oracle Communications Cloud Native Core Policy. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.
Affected software
MySQL Enterprise Monitor
Oracle Communications Cloud Native Core Network Repository Function
IBM Process Mining
How to mitigate CVE-2021-22119
IBM Process Mining - update to 1.14.1