PT-2011-1520 · Oracle · Oracle Goldengate Veridata

Andrea Micalizzi

+1

·

Published

2011-01-18

·

Updated

2017-08-17

·

CVE-2010-4416

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle GoldenGate Veridata version 3.0.0.4
Description The issue affects the availability of the system. It is reportedly related to the parsing of XML SOAP requests by the Server component. A reliable third-party researcher claims this could be a buffer overflow vulnerability, potentially triggered by a crafted XML SOAP request with a value lacking the expected 0x20 terminator character.
Recommendations For Oracle GoldenGate Veridata version 3.0.0.4, consider restricting access to the Server component to minimize the risk of exploitation until a patch is available. Avoid using crafted XML SOAP requests that could trigger the buffer overflow. As a temporary workaround, consider implementing additional validation on XML SOAP requests to ensure they contain the expected 0x20 terminator character.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2010-4416
ZDI-11-019

Affected Products

Oracle Goldengate Veridata