VDB
GCVE-110-NCSC-2024-297
GCVE-110-NCSC-2024-297
Advisory PublishedCVSS 9.8/10
Er zijn kwetsbaarheden verholpen in Oracle Financial Services Applications.
Weaknesses (CWE)
CWE-502Deserialization of Untrusted DataCWE-328Use of Weak HashCWE-426Untrusted Search PathCWE-400Uncontrolled Resource ConsumptionCWE-532Insertion of Sensitive Information into Log FileCWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-121Stack-based Buffer OverflowCWE-404Improper Resource Shutdown or ReleaseCWE-601URL Redirection to Untrusted Site ('Open Redirect')CWE-416Use After FreeCWE-20Improper Input ValidationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-770Allocation of Resources Without Limits or ThrottlingCWE-787Out-of-bounds WriteCWE-306Missing Authentication for Critical Function
Risk Scores
CVSS 3.1
9.8/10
Critical · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| oracle | financial_services_cash_flow_engine | — | — |
| oracle | financial_services_lending_and_leasing | — | — |
| oracle | financial_services_trade-based_anti_money_laundering_enterprise_edition | — | — |
| oracle | financial_services_analytical_applications_infrastructure | — | — |
| oracle | financial_services_compliance_studio | — | — |
| oracle | financial_services_behavior_detection_platform | — | — |
| oracle | financial_services_revenue_management_and_billing | — | — |
| oracle | financial_services_enterprise_case_management | — | — |
| oracle | financial_services_basel_regulatory_capital_internal_ratings_based_approach | — | — |
| oracle | financial_services_model_management_and_governance | — | — |
| oracle | financial_services_basel_regulatory_capital_basic | — | — |
References
Browse GCVE Records
74,267 records in the GCVE database · Updated July 22, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.