Improper input validation in Oracle Communications Cloud Native Core Automated Test Suite - CVE-2021-22132

 

Improper input validation in Oracle Communications Cloud Native Core Automated Test Suite - CVE-2021-22132

Published: April 22, 2022


Vulnerability identifier: #VU62514
CSH Severity: Medium
CVSS v4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-22132
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to gain access to sensitive information.

The vulnerability exists due to improper input validation within the Automated Test Suite Framework (Elasticsearch) component in Oracle Communications Cloud Native Core Automated Test Suite. A remote authenticated user can exploit this vulnerability to gain access to sensitive information.


Affected software

Oracle Communications Cloud Native Core Automated Test Suite
Red Hat Integration Camel Extensions for Quarkus
Red Hat Integration Camel-K

How to mitigate CVE-2021-22132

Install updates from vendor's website.

Red Hat Integration Camel-K - update to 1.8

External References

Related Security Bulletins