Improper input validation in Oracle Retail Customer Management and Segmentation Foundation - CVE-2023-39017

 

Improper input validation in Oracle Retail Customer Management and Segmentation Foundation - CVE-2023-39017

Published: October 17, 2023 / Updated: December 26, 2023


Vulnerability identifier: #VU82172
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-39017
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Operations (Quartz) component in Oracle Retail Customer Management and Segmentation Foundation. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Retail Customer Management and Segmentation Foundation
IBM Sterling Partner Engagement Manager
IBM Fusion HCI
IBM Maximo Application Suite
PowerProtect Data Manager

How to mitigate CVE-2023-39017

Install updates from vendor's website.

IBM Sterling Partner Engagement Manager - addressed in versions 6.2.3.5, 6.2.4.2
IBM Fusion HCI - update to 2.7.1
IBM Maximo Application Suite - addressed in versions 8.7.5, 8.8.1
PowerProtect Data Manager - update to 19.19.0-15

External References

Related Security Bulletins