VDB
GCVE-110-NCSC-2024-411
GCVE-110-NCSC-2024-411
Advisory PublishedCVSS 7.5/10
Access of Resource Using Incompatible Type ('Type Confusion')
Weaknesses (CWE)
CWE-275-CWE-502Deserialization of Untrusted DataCWE-192Integer Coercion ErrorCWE-87Improper Neutralization of Alternate XSS SyntaxCWE-190Integer Overflow or WraparoundCWE-311Missing Encryption of Sensitive DataCWE-400Uncontrolled Resource ConsumptionCWE-552Files or Directories Accessible to External PartiesCWE-834Excessive IterationCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-122Heap-based Buffer OverflowCWE-770Allocation of Resources Without Limits or ThrottlingCWE-426Untrusted Search PathCWE-787Out-of-bounds WriteCWE-20Improper Input ValidationCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-295Improper Certificate ValidationCWE-639Authorization Bypass Through User-Controlled KeyCWE-404Improper Resource Shutdown or ReleaseCWE-222Truncation of Security-relevant InformationCWE-476NULL Pointer DereferenceCWE-304Missing Critical Step in AuthenticationCWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')CWE-203Observable DiscrepancyCWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')CWE-606Unchecked Input for Loop ConditionCWE-416Use After FreeCWE-116Improper Encoding or Escaping of OutputCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-1333Inefficient Regular Expression ComplexityCWE-125Out-of-bounds ReadCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-427Uncontrolled Search Path ElementCWE-401Missing Release of Memory after Effective LifetimeCWE-755Improper Handling of Exceptional ConditionsCWE-130Improper Handling of Length Parameter InconsistencyCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-918Server-Side Request Forgery (SSRF)CWE-172Encoding ErrorCWE-284Improper Access ControlCWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')CWE-18-
Risk Scores
CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| oracle | application_express_team_calendar_plugin | — | — |
| oracle | fleet_patching_and_provisioning | — | — |
| oracle | oracle_sql_developer | — | — |
| oracle | application_express | — | — |
| oracle | fleet_patching_and_provisioning_-_micronaut | — | — |
| oracle | sqlcl | — | — |
| oracle | autonomous_health_framework | — | — |
| oracle | goldengate_veridata | — | — |
| oracle | essbase | — | — |
| oracle | goldengate_big_data | — | — |
| oracle | goldengate | — | — |
| oracle | oracle_nosql_database | — | — |
| oracle | nosql_database | — | — |
| oracle | database_-_java_vm | — | — |
| oracle_corporation | oracle_application_express | — | — |
| oracle | secure_backup | — | — |
| oracle | spatial_and_graph_mapviewer | — | — |
| oracle | oracle_goldengate | — | — |
| oracle | goldengate_big_data_and_application_adapters | — | — |
| oracle | goldengate_studio | — | — |
| oracle | blockchain_platform | — | — |
| oracle | database_-_core | — | — |
| oracle | database_-_security | — | — |
| oracle | application_express_administration | — | — |
| oracle | oracle_goldengate_studio | — | — |
| oracle | goldengate_stream_analytics | — | — |
| oracle | application_express_customers_plugin | — | — |
| oracle | database_-_xml_database | — | — |
| oracle | spatial_and_graph | — | — |
| oracle | oracle_secure_backup | — | — |
| oracle | oracle_goldengate_stream_analytics | — | — |
| oracle | graalvm_for_jdk | — | — |
| oracle | database_-_grid | — | — |
| oracle | management_pack_for__goldengate | — | — |
| oracle | oracle_essbase | — | — |
| oracle | sql_developer | — | — |
Aliases
CVE-2022-1471CVE-2022-34169CVE-2022-36033CVE-2022-37454CVE-2022-38136CVE-2022-40196CVE-2022-41342CVE-2022-42919CVE-2022-45061CVE-2022-46337CVE-2023-26031CVE-2023-26551CVE-2023-26552CVE-2023-26553CVE-2023-26554CVE-2023-26555CVE-2023-28484CVE-2023-29469CVE-2023-2976CVE-2023-33201CVE-2023-37920CVE-2023-39410CVE-2023-4043CVE-2023-44487CVE-2023-44981CVE-2023-45288CVE-2023-4759CVE-2023-4863CVE-2023-48795CVE-2023-49083CVE-2023-5072CVE-2023-51384CVE-2023-51385CVE-2023-52425CVE-2023-52426CVE-2024-1874CVE-2024-21131CVE-2024-21138CVE-2024-21140CVE-2024-21144CVE-2024-21145CVE-2024-21147CVE-2024-21233CVE-2024-21242CVE-2024-21251CVE-2024-21261CVE-2024-22018CVE-2024-22020CVE-2024-22201CVE-2024-23807CVE-2024-23944CVE-2024-2408CVE-2024-24989CVE-2024-24990CVE-2024-2511CVE-2024-25710CVE-2024-26130CVE-2024-26308CVE-2024-27983CVE-2024-28182CVE-2024-28849CVE-2024-28887CVE-2024-29025CVE-2024-29131CVE-2024-29133CVE-2024-31079CVE-2024-32760CVE-2024-34161CVE-2024-34750CVE-2024-35200CVE-2024-36137CVE-2024-36138CVE-2024-36387CVE-2024-37370CVE-2024-37371CVE-2024-37372CVE-2024-38356CVE-2024-38357CVE-2024-38472CVE-2024-38473CVE-2024-38474CVE-2024-38475CVE-2024-38476CVE-2024-38477CVE-2024-38998CVE-2024-38999CVE-2024-39573CVE-2024-39884CVE-2024-40725CVE-2024-40898CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-4577CVE-2024-45801CVE-2024-4603CVE-2024-4741CVE-2024-5458CVE-2024-5535CVE-2024-5585CVE-2024-6119CVE-2024-6232CVE-2024-7264CVE-2024-7592
References
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.