VDB

GCVE-110-NCSC-2024-411

GCVE-110-NCSC-2024-411
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published October 17, 2024
Access of Resource Using Incompatible Type ('Type Confusion')

Weaknesses (CWE)

CWE-275-CWE-502Deserialization of Untrusted DataCWE-192Integer Coercion ErrorCWE-87Improper Neutralization of Alternate XSS SyntaxCWE-190Integer Overflow or WraparoundCWE-311Missing Encryption of Sensitive DataCWE-400Uncontrolled Resource ConsumptionCWE-552Files or Directories Accessible to External PartiesCWE-834Excessive IterationCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-122Heap-based Buffer OverflowCWE-770Allocation of Resources Without Limits or ThrottlingCWE-426Untrusted Search PathCWE-787Out-of-bounds WriteCWE-20Improper Input ValidationCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-295Improper Certificate ValidationCWE-639Authorization Bypass Through User-Controlled KeyCWE-404Improper Resource Shutdown or ReleaseCWE-222Truncation of Security-relevant InformationCWE-476NULL Pointer DereferenceCWE-304Missing Critical Step in AuthenticationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-203Observable DiscrepancyCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-606Unchecked Input for Loop ConditionCWE-416Use After FreeCWE-116Improper Encoding or Escaping of OutputCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-1333Inefficient Regular Expression ComplexityCWE-125Out-of-bounds ReadCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-427Uncontrolled Search Path ElementCWE-401Missing Release of Memory after Effective LifetimeCWE-755Improper Handling of Exceptional ConditionsCWE-130Improper Handling of Length Parameter InconsistencyCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-918Server-Side Request Forgery (SSRF)CWE-172Encoding ErrorCWE-284Improper Access ControlCWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')CWE-18-

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersionsPlatforms
oracleapplication_express_team_calendar_plugin
oraclefleet_patching_and_provisioning
oracleoracle_sql_developer
oracleapplication_express
oraclefleet_patching_and_provisioning_-_micronaut
oraclesqlcl
oracleautonomous_health_framework
oraclegoldengate_veridata
oracleessbase
oraclegoldengate_big_data
oraclegoldengate
oracleoracle_nosql_database
oraclenosql_database
oracledatabase_-_java_vm
oracle_corporationoracle_application_express
oraclesecure_backup
oraclespatial_and_graph_mapviewer
oracleoracle_goldengate
oraclegoldengate_big_data_and_application_adapters
oraclegoldengate_studio
oracleblockchain_platform
oracledatabase_-_core
oracledatabase_-_security
oracleapplication_express_administration
oracleoracle_goldengate_studio
oraclegoldengate_stream_analytics
oracleapplication_express_customers_plugin
oracledatabase_-_xml_database
oraclespatial_and_graph
oracleoracle_secure_backup
oracleoracle_goldengate_stream_analytics
oraclegraalvm_for_jdk
oracledatabase_-_grid
oraclemanagement_pack_for__goldengate
oracleoracle_essbase
oraclesql_developer

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›