Vulnerabilities Patched in Oracle Database Server and Oracle REST Data Services (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- Oracle REST Data Services (24.2.0-26.1.0): takeover, data access, DoS
- Oracle Database Server (23.4.0-23.26.2): unauthenticated compromise of Net Service
- Eclipse Jetty request smuggling (no patch available)
"Oracle has fixed vulnerabilities in Oracle REST Data Services (versions 24.2.0 to 26.1.0) and Oracle Database Server (versions 23.4.0 to 23.26.2). Low-privileged attackers with network access via HTTPS can fully take over services, access or modify data, and cause denial-of-service. In Oracle Database Server, unauthenticated attackers can compromise the Net Service via TLS. Additionally, a vulnerability in Eclipse Jetty's HTTP/1.1 parser enables request smuggling; no patch is available yet."
no comments yet.