Improper input validation in Oracle Outside In Technology - CVE-2024-21120
Published: April 17, 2024
Vulnerability identifier: #VU88643
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-21120
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to read and manipulate data.
The vulnerability exists due to improper input validation within the Outside In Core component in Oracle Outside In Technology. A local authenticated user can exploit this vulnerability to read and manipulate data.
Affected software
Oracle Outside In Technology
IBM Engineering Requirements Management DOORS Next
IBM Engineering Requirements Management DOORS Next
How to mitigate CVE-2024-21120
Install updates from vendor's website.
IBM Engineering Requirements Management DOORS Next - addressed in versions 7.0.2 ifix 30, 7.0.3 ifix 7