Improper input validation in Oracle Database Server - CVE-2023-36632

 

Improper input validation in Oracle Database Server - CVE-2023-36632

Published: April 16, 2024


Vulnerability identifier: #VU88572
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-36632
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to perform service disruption.

The vulnerability exists due to improper input validation within the RDBMS (Python) in Oracle Database Server. A remote authenticated user can exploit this vulnerability to perform service disruption.


Affected software

Oracle Database Server
IBM Cloud Transformation Advisor
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
PowerProtect Data Manager

How to mitigate CVE-2023-36632

Install updates from vendor's website.

IBM Cloud Transformation Advisor - update to 3.10.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1
PowerProtect Data Manager - update to 19.19.0-15

External References

Related Security Bulletins