Improper input validation in Oracle Smart View for Office - CVE-2023-29081

 

Improper input validation in Oracle Smart View for Office - CVE-2023-29081

Published: April 17, 2024


Vulnerability identifier: #VU88661
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-29081
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Authentication (InstallShield) component in Oracle Smart View for Office. A local authenticated user can exploit this vulnerability to perform a denial of service (DoS) attack.


Affected software

Oracle Smart View for Office
Infrastructure Technology
Oracle Hyperion Data Relationship Management
Oracle Life Sciences Central Coding
Oracle Communications ASAP
MyDell
Hyperion Financial Close Management
Oracle WebCenter Content
Oracle Documaker
Dell Precision Optimizer

How to mitigate CVE-2023-29081

Install updates from vendor's website.

MyDell - update to 3.2.308.1
Dell Precision Optimizer - update to 4.2.2.0

External References

Related Security Bulletins