Improper input validation in Oracle Communications Billing and Revenue Management - CVE-2023-47100
Published: April 16, 2024
Vulnerability identifier: #VU88575
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-47100
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The vulnerability exists due to improper input validation within the Platform (Perl) component in Oracle Communications Billing and Revenue Management. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Communications Billing and Revenue Management
Amazon Linux AMI
macOS
openEuler
IBM AIX
Astronomer with IBM
watsonx.data
IBM VIOS
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
perl
perl-help
perl-debuginfo
perl-devel
perl-libs
perl-debugsource
Amazon Linux AMI
macOS
openEuler
IBM AIX
Astronomer with IBM
watsonx.data
IBM VIOS
Oracle Communications Cloud Native Core Network Repository Function
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
perl
perl-help
perl-debuginfo
perl-devel
perl-libs
perl-debugsource
How to mitigate CVE-2023-47100
Install updates from vendor's website.
Oracle Communications Billing and Revenue Management - update to 12.0.0.8.0
Astronomer with IBM - update to 0.37.1
watsonx.data - update to 2.0.2
macOS - update to 15.2 24C101
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
perl - update to 5.32.1-477
perl-help - addressed in versions 5.34.0-12, 5.34.0-13
perl-debuginfo - addressed in versions 5.34.0-12, 5.34.0-13
perl-devel - addressed in versions 5.34.0-12, 5.34.0-13
perl - addressed in versions 5.34.0-12, 5.34.0-13
perl-libs - addressed in versions 5.34.0-12, 5.34.0-13
perl-debugsource - addressed in versions 5.34.0-12, 5.34.0-13
IBM AIX - addressed in versions 7.3.1, 7.3.1.2
Astronomer with IBM - update to 0.37.1
watsonx.data - update to 2.0.2
macOS - update to 15.2 24C101
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.8
perl - update to 5.32.1-477
perl-help - addressed in versions 5.34.0-12, 5.34.0-13
perl-debuginfo - addressed in versions 5.34.0-12, 5.34.0-13
perl-devel - addressed in versions 5.34.0-12, 5.34.0-13
perl - addressed in versions 5.34.0-12, 5.34.0-13
perl-libs - addressed in versions 5.34.0-12, 5.34.0-13
perl-debugsource - addressed in versions 5.34.0-12, 5.34.0-13
IBM AIX - addressed in versions 7.3.1, 7.3.1.2
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Repository Function
- Improper input validation in Oracle Communications Billing and Revenue Management
- Multiple vulnerabilities in IBM AIX and VIOS
- openEuler 22.03 LTS SP2 update for perl
- openEuler 22.03 LTS update for perl
- openEuler 22.03 LTS SP1 update for perl
- Improper input validation in IBM watsonx.data
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge
- Amazon Linux AMI update for perl
- Astronomer with IBM update for Perl
- Multiple vulnerabilities in macOS Sequoia