Improper input validation in Oracle Communications Unified Inventory Management - CVE-2022-34381

 

Improper input validation in Oracle Communications Unified Inventory Management - CVE-2022-34381

Published: April 16, 2024


Vulnerability identifier: #VU88576
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-34381
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Security (BSAFE Crypto-J) component in Oracle Communications Unified Inventory Management. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Communications Unified Inventory Management
Oracle StorageTek Tape Analytics (STA)
Oracle Communications Network Integrity
Oracle HTTP Server
Enterprise Manager Base Platform
Oracle Communications Billing and Revenue Management
Oracle Application Testing Suite
Oracle Retail Service Backbone
Oracle Retail Store Inventory Management
Oracle Retail Integration Bus

How to mitigate CVE-2022-34381

Install updates from vendor's website.


External References

Related Security Bulletins