Oracle fixes 158 vulnerabilities in database products (advisories.ncsc.nl)
0xBASE INTEL BRIEF
- 158 vulnerabilities fixed, 91 from third-party or not exploitable.
- Six vulnerabilities with CVSS 9+.
- HTTP request smuggling in Oracle REST Data Services (Eclipse Jetty).
- Vulnerable Perl module Compress::Raw::Zlib.
- Apache Kafka JWT token validation bypassed.
- Oracle Net Services leaks sensitive information.
- TimesTen and RDBMS fully takeover.
"Oracle has fixed 158 vulnerabilities across multiple database products, including Oracle Database Server and APEX. Six vulnerabilities have a CVSS score of 9 or higher. Specific vulnerabilities include HTTP request smuggling in Oracle REST Data Services, vulnerabilities in Perl's Compress::Raw::Zlib, unauthorized access via Apache Kafka, and full database takeover via Oracle Net Services and TimesTen."
no comments yet.