PT-2011-1520 · Oracle · Oracle Goldengate Veridata

Andrea Micalizzi

+1

·

Publicado

2011-01-18

·

Atualizado

2017-08-17

·

CVE-2010-4416

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle GoldenGate Veridata version 3.0.0.4
Description The issue affects the availability of the system. It is reportedly related to the parsing of XML SOAP requests by the Server component. A reliable third-party researcher claims this could be a buffer overflow vulnerability, potentially triggered by a crafted XML SOAP request with a value lacking the expected 0x20 terminator character.
Recommendations For Oracle GoldenGate Veridata version 3.0.0.4, consider restricting access to the Server component to minimize the risk of exploitation until a patch is available. Avoid using crafted XML SOAP requests that could trigger the buffer overflow. As a temporary workaround, consider implementing additional validation on XML SOAP requests to ensure they contain the expected 0x20 terminator character.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2010-4416
ZDI-11-019

Produtos afetados

Oracle Goldengate Veridata