PT-2011-1520 · Oracle · Oracle Goldengate Veridata
Andrea Micalizzi
+1
·
Publicado
2011-01-18
·
Atualizado
2017-08-17
·
CVE-2010-4416
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle GoldenGate Veridata version 3.0.0.4
Description
The issue affects the availability of the system. It is reportedly related to the parsing of XML SOAP requests by the Server component. A reliable third-party researcher claims this could be a buffer overflow vulnerability, potentially triggered by a crafted XML SOAP request with a value lacking the expected 0x20 terminator character.
Recommendations
For Oracle GoldenGate Veridata version 3.0.0.4, consider restricting access to the Server component to minimize the risk of exploitation until a patch is available. Avoid using crafted XML SOAP requests that could trigger the buffer overflow. As a temporary workaround, consider implementing additional validation on XML SOAP requests to ensure they contain the expected 0x20 terminator character.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Goldengate Veridata