Improper input validation in Oracle Financial Services Model Management and Governance - CVE-2023-26031
Published: July 18, 2024
Vulnerability identifier: #VU94546
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26031
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Installer (Apache Hadoop) component in Oracle Financial Services Model Management and Governance. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
Affected software
Oracle Financial Services Model Management and Governance
Oracle Analytics Desktop
Oracle Financial Services Compliance Studio
Oracle Analytics Desktop
Oracle Financial Services Compliance Studio
How to mitigate CVE-2023-26031
Install updates from vendor's website.