PT-2022-4640 · Oracle · Oracle Coherence
Thiscodecc
·
Published
2022-07-19
·
Updated
2022-07-26
·
CVE-2022-21570
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Coherence versions 3.7.1.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0
Description
The issue is related to insufficient input validation in the Core component of Oracle Coherence, allowing an unauthenticated attacker with network access via T3 or IIOP protocols to compromise Oracle Coherence. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence.
Recommendations
For versions 3.7.1.0, 12.2.1.3.0, 12.2.1.4.0, and 14.1.1.0.0, consider restricting network access via T3 and IIOP protocols to minimize the risk of exploitation. As a temporary workaround, limit the ability of remote attackers to cause a hang or crash of Oracle Coherence by implementing additional security measures, such as network segmentation or intrusion detection systems. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Resource Release
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Coherence