Improper input validation in Oracle Financial Services Model Management and Governance - CVE-2023-26031

 

Improper input validation in Oracle Financial Services Model Management and Governance - CVE-2023-26031

Published: July 18, 2024


Vulnerability identifier: #VU94546
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26031
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Installer (Apache Hadoop) component in Oracle Financial Services Model Management and Governance. A remote authenticated user can exploit this vulnerability to execute arbitrary code.


Affected software

Oracle Financial Services Model Management and Governance
Oracle Analytics Desktop
Oracle Financial Services Compliance Studio

How to mitigate CVE-2023-26031

Install updates from vendor's website.


External References

Related Security Bulletins