PT-2023-3697 · Oracle · Application Express Administration

Dirk Van Veen

·

Publicado

2023-07-18

·

Atualizado

2023-07-27

·

CVE-2023-21983

CVSS v3.1

5.6

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Application Express Administration versions 18.2 through 22.2
Description The issue is related to insufficient input validation in the Application Express Administration product of Oracle Application Express. It allows an unauthenticated attacker with network access via HTTP to compromise the Application Express Administration. Successful attacks can result in unauthorized update, insert, or delete access to some data, as well as unauthorized read access to a subset of data and the ability to cause a partial denial of service.
Recommendations For versions 18.2 through 22.2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Application Express Administration product to minimize the risk of exploitation. Avoid using the HTTP protocol to access the Application Express Administration until the issue is resolved. Restrict network access to the Application Express Administration product to prevent unauthorized attacks.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-03985
CVE-2023-21983

Produtos afetados

Application Express Administration