SB2024041738 - Multiple vulnerabilities in Oracle Access Manager



SB2024041738 - Multiple vulnerabilities in Oracle Access Manager

Published: April 17, 2024

Security Bulletin ID SB2024041738
Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 67% Low 33%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Security features bypass (CVE-ID: CVE-2022-24329)

The vulnerability allows a remote user to bypass certain security restrictions.

The vulnerability exists due to unspecified error, related to the ability to lock dependencies for Kotlin Multiplatform Gradle projects.



2) Cleartext transmission of sensitive information (CVE-ID: CVE-2019-0231)

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to incorrect handling of close_notify SSL/TLS messages that results in software not closing the connection and retaining the socket opened, which allows a client to receive clear text messages afterward. A remote attacker can intercept traffic between client and server application and gain access to potentially sensitive information.


3) Integer overflow (CVE-ID: CVE-2023-37536)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow. A remote attacker can pass specially crafted data to the application, trigger integer overflow and perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.