Improper input validation in Oracle Communications Cloud Native Core Unified Data Repository - CVE-2020-14340

 

Improper input validation in Oracle Communications Cloud Native Core Unified Data Repository - CVE-2020-14340

Published: January 27, 2022


Vulnerability identifier: #VU60097
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-14340
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the UDR (XNIO) component in Oracle Communications Cloud Native Core Unified Data Repository. A remote non-authenticated attacker can exploit this vulnerability to perform a denial of service (DoS) attack.


Affected software

Oracle Communications Cloud Native Core Unified Data Repository
Oracle Communications Cloud Native Core Console
Oracle Communications Cloud Native Core Service Communication Proxy
Oracle Communications Cloud Native Core Policy
Oracle Communications Cloud Native Core Security Edge Protection Proxy
Splunk Add-on for JBoss
Oracle Communications Cloud Native Core Network Repository Function

How to mitigate CVE-2020-14340

Install updates from vendor's website.

Splunk Add-on for JBoss - update to 3.1.1

External References

Related Security Bulletins