Improper input validation in Oracle Retail Customer Management and Segmentation Foundation - CVE-2023-39017
Published: October 17, 2023 / Updated: December 26, 2023
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Operations (Quartz) component in Oracle Retail Customer Management and Segmentation Foundation. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
IBM Sterling Partner Engagement Manager
IBM Fusion HCI
IBM Maximo Application Suite
PowerProtect Data Manager
How to mitigate CVE-2023-39017
IBM Fusion HCI - update to 2.7.1
IBM Maximo Application Suite - addressed in versions 8.7.5, 8.8.1
PowerProtect Data Manager - update to 19.19.0-15
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Retail Customer Management and Segmentation Foundation
- IBM Maximo Application Suite - IoT Component update for Quartz Job Scheduler
- Multiple vulnerabilities in IBM Storage Fusion HCI
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- IBM Sterling Partner Engagement Manager Essentials Edition update for quartz-jobs