VDB

GCVE-110-NCSC-2026-79

GCVE-110-NCSC-2026-79
Advisory PublishedCVSS 7.5/10
Vulnetix · Advisory published March 10, 2026
Multiple vulnerabilities across Oracle products, including Utilities Application Framework, Fusion Middleware, and WebLogic Server, allow unauthenticated attackers to execute denial of service attacks, with CVSS scores of 7.5 and varying damage ratings.

Weaknesses (CWE)

CWE-20Improper Input ValidationCWE-208Observable Timing DiscrepancyCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-295Improper Certificate ValidationCWE-197Numeric Truncation ErrorCWE-330Use of Insufficiently Random ValuesCWE-125Out-of-bounds ReadCWE-1333Inefficient Regular Expression ComplexityCWE-436Interpretation ConflictCWE-923Improper Restriction of Communication Channel to Intended EndpointsCWE-79Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')CWE-444Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')CWE-200Exposure of Sensitive Information to an Unauthorized ActorCWE-770Allocation of Resources Without Limits or ThrottlingCWE-940Improper Verification of Source of a Communication ChannelCWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')CWE-134Use of Externally-Controlled Format StringCWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')CWE-190Integer Overflow or WraparoundCWE-674Uncontrolled RecursionCWE-201Insertion of Sensitive Information Into Sent DataCWE-184Incomplete List of Disallowed InputsCWE-288Authentication Bypass Using an Alternate Path or ChannelCWE-787Out-of-bounds WriteCWE-121Stack-based Buffer OverflowCWE-130Improper Handling of Length Parameter InconsistencyCWE-73External Control of File Name or Path

Risk Scores

CVSS 3.1
7.5/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersionsPlatforms
Siemensvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,237 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›