VDB
GCVE-110-NCSC-2025-27
GCVE-110-NCSC-2025-27
Advisory PublishedCVSS 5.5/10
Oracle heeft meerdere kwetsbaarheden verholpen in zijn producten, waaronder Oracle Fusion Middleware, Oracle WebLogic Server, en Oracle HTTP Server.
Weaknesses (CWE)
CWE-611Improper Restriction of XML External Entity ReferenceCWE-787Out-of-bounds WriteCWE-113Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')CWE-502Deserialization of Untrusted DataCWE-532Insertion of Sensitive Information into Log FileCWE-732Incorrect Permission Assignment for Critical ResourceCWE-400Uncontrolled Resource ConsumptionCWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-843Access of Resource Using Incompatible Type ('Type Confusion')CWE-295Improper Certificate ValidationCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-208Observable Timing DiscrepancyCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-706Use of Incorrectly-Resolved Name or ReferenceCWE-755Improper Handling of Exceptional ConditionsCWE-130Improper Handling of Length Parameter InconsistencyCWE-172Encoding ErrorCWE-284Improper Access ControlCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')CWE-918Server-Side Request Forgery (SSRF)CWE-190Integer Overflow or WraparoundCWE-121Stack-based Buffer Overflow
Risk Scores
CVSS 3.1
5.5/10
Medium · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| oracle | business_process_management_suite | — | — |
| oracle | webcenter_portal | — | — |
| oracle | weblogic_server | — | — |
| oracle | identity_manager | — | — |
| oracle | security_service | — | — |
| oracle | fusion_middleware_mapviewer | — | — |
| oracle | business_activity_monitoring | — | — |
| oracle | fusion_middleware | — | — |
| oracle | outside_in_technology | — | — |
| oracle | middleware_common_libraries_and_tools | — | — |
| oracle | managed_file_transfer | — | — |
| oracle | business_activity_monitoring__bam_ | — | — |
| oracle | http_server | — | — |
Aliases
CVE-2019-12415CVE-2023-38709CVE-2023-39410CVE-2023-44483CVE-2023-49582CVE-2023-51775CVE-2023-7272CVE-2024-23635CVE-2024-29857CVE-2024-30171CVE-2024-30172CVE-2024-34447CVE-2024-34750CVE-2024-37370CVE-2024-37371CVE-2024-38473CVE-2024-38475CVE-2024-38816CVE-2024-38819CVE-2024-38998CVE-2024-38999CVE-2024-40898CVE-2024-45490CVE-2024-45491CVE-2024-45492CVE-2024-47072CVE-2024-47554CVE-2024-47561CVE-2024-5535CVE-2024-6119CVE-2024-8096CVE-2025-21498CVE-2025-21535CVE-2025-21549
References
Browse GCVE Records
75,828 records in the GCVE database · Updated August 4, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.