Improper input validation in Oracle Communications Billing and Revenue Management - CVE-2023-47100

 

Improper input validation in Oracle Communications Billing and Revenue Management - CVE-2023-47100

Published: April 16, 2024


Vulnerability identifier: #VU88575
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-47100
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Platform (Perl) component in Oracle Communications Billing and Revenue Management. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Communications Billing and Revenue Management
Amazon Linux AMI
macOS
openEuler
IBM AIX
Astronomer with IBM
watsonx.data
IBM VIOS
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
perl
perl-help
perl-debuginfo
perl-devel
perl-libs
perl-debugsource

How to mitigate CVE-2023-47100

Install updates from vendor's website.

Oracle Communications Billing and Revenue Management - update to 12.0.0.8.0
Astronomer with IBM - update to 0.37.1
watsonx.data - update to 2.0.2
macOS - update to 15.2 24C101
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
perl - update to 5.32.1-477
perl-help - addressed in versions 5.34.0-12, 5.34.0-13
perl-debuginfo - addressed in versions 5.34.0-12, 5.34.0-13
perl-devel - addressed in versions 5.34.0-12, 5.34.0-13
perl - addressed in versions 5.34.0-12, 5.34.0-13
perl-libs - addressed in versions 5.34.0-12, 5.34.0-13
perl-debugsource - addressed in versions 5.34.0-12, 5.34.0-13
IBM AIX - addressed in versions 7.3.1, 7.3.1.2

External References

Related Security Bulletins