PT-2023-6208 · Oracle · Oracle Enterprise Command Center Framework

Nils Putnins

·

Published

2023-10-17

·

Updated

2023-10-23

·

CVE-2023-22107

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Enterprise Command Center Framework versions 8 through 10
Description The issue is related to insufficient input validation in the UI Components of the Oracle Enterprise Command Center Framework, allowing an unauthenticated attacker with network access via HTTP to compromise the framework. Successful attacks require human interaction from a person other than the attacker and may significantly impact additional products. Attacks can result in unauthorized update, insert, or delete access to some of the framework's accessible data, as well as unauthorized read access to a subset of the framework's accessible data.
Recommendations For versions 8 through 10, consider restricting access to the UI Components until a patch is available. As a temporary workaround, limit the use of HTTP protocol to minimize the risk of exploitation. Avoid using the framework's accessible data in a way that could lead to unauthorized access until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-06917
CVE-2023-22107

Affected Products

Oracle Enterprise Command Center Framework