ENISA EUVD · EUVD-2024-41511Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2025-0148Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0143Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2025-0144Oracle Financial Services Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Financial Services Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2024-3195Oracle Communications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2024-3191Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2024-3196Oracle Communications Applications: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Communications Applications ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2024-1951expat: Mehrere Schwachstellen ermöglichen Denial of ServiceEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in expat ausnutzen, um einen Denial of Service Angriff durchzuführen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20240904Security Bulletin 04 Sep 2024The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 04 Sep 2024, published on 4 September 2024. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0218Multiples vulnérabilités dans les produits VMwareord?id=CVE-2024-37407
Référence CVE CVE-2024-37891
https://www.cve.org/CVERecord?id=CVE-2024-37891
Référence CVE CVE-2024-38816
https://www.cve.org/CVERecord?id=CVE-2024-38816
Référence CVE CVE-2024-38819
https://www.cve.org/CVERecord?id=CVE-2024-38819
Référence CVE CVE-2024-38828
https://www.cve.org/CVERecord?id=CVE-2024-38828
Référence CVE CVE-2024-4032
https://www.cve.org/CVERecord?id=CVE-2024-4032
Référence CVE CVE-2024-45337
https://www.cve.org/CVERecord?id=CVE-2024-45337
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-4603
https://www.cve.org/CVERecord?id=CVE-2024-4603
Référence CVE CVE-2024-4741
https://www.cve.org/CVERecord?id=CVE-2024-4741
Référence CVE CVE-2024-47535
https://www.cve.org/CVERecord?id=CVE-2024-47535
Référence CVE CVE-2024-47611
https://www.cve.org/CVERecord?id=CVE-2024-47611
Référence CVE CVE-2024-48615
https://www.cve.org/CVERecord?id=CVE-2024-48615
Référence CVE CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
Référence CVE CVE-2024-51744
https://www.cve.org/CVERecord?id=CVE-2024-51744
Référence CVE CVE-2024-52533
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-1057Multiples vulnérabilités dans les produits VMwared?id=CVE-2024-45019
Référence CVE CVE-2024-45020
https://www.cve.org/CVERecord?id=CVE-2024-45020
Référence CVE CVE-2024-45022
https://www.cve.org/CVERecord?id=CVE-2024-45022
Référence CVE CVE-2024-45027
https://www.cve.org/CVERecord?id=CVE-2024-45027
Référence CVE CVE-2024-45029
https://www.cve.org/CVERecord?id=CVE-2024-45029
Référence CVE CVE-2024-45336
https://www.cve.org/CVERecord?id=CVE-2024-45336
Référence CVE CVE-2024-45341
https://www.cve.org/CVERecord?id=CVE-2024-45341
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-4603
https://www.cve.org/CVERecord?id=CVE-2024-4603
Référence CVE CVE-2024-46672
https://www.cve.org/CVERecord?id=CVE-2024-46672
Référence CVE CVE-2024-46692
https://www.cve.org/CVERecord?id=CVE-2024-46692
Référence CVE CVE-2024-46697
https://www.cve.org/CVERecord?id=CVE-2024-46697
Référence CVE CVE-2024-46698
https://www.cve.org/CVERecord?id=CVE-2024-46698
Référence CVE CVE-2024-46706
https://www.cve.org/CVERecord?id=CVE-2024-46706
Référence CVE CVE-2024-46709
https://www.cve.org/CVERecord?id=CVE-2024-46709
Référence CVE CVE-2024-46710
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0969Multiples vulnérabilités dans les produits VMwared?id=CVE-2024-43788
Référence CVE CVE-2024-43790
https://www.cve.org/CVERecord?id=CVE-2024-43790
Référence CVE CVE-2024-43802
https://www.cve.org/CVERecord?id=CVE-2024-43802
Référence CVE CVE-2024-44939
https://www.cve.org/CVERecord?id=CVE-2024-44939
Référence CVE CVE-2024-45336
https://www.cve.org/CVERecord?id=CVE-2024-45336
Référence CVE CVE-2024-45337
https://www.cve.org/CVERecord?id=CVE-2024-45337
Référence CVE CVE-2024-45341
https://www.cve.org/CVERecord?id=CVE-2024-45341
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-45720
https://www.cve.org/CVERecord?id=CVE-2024-45720
Référence CVE CVE-2024-45993
https://www.cve.org/CVERecord?id=CVE-2024-45993
Référence CVE CVE-2024-4603
https://www.cve.org/CVERecord?id=CVE-2024-4603
Référence CVE CVE-2024-46901
https://www.cve.org/CVERecord?id=CVE-2024-46901
Référence CVE CVE-2024-47081
https://www.cve.org/CVERecord?id=CVE-2024-47081
Référence CVE CVE-2024-4741
https://www.cve.org/CVERecord?id=CVE-2024-4741
Référence CVE CVE-2024-47535
https://www.cve.org/CVERecord?id=CVE-2024-47535
Référence CVE CVE-2024-47554
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0864Multiples vulnérabilités dans VMware Tanzuecord?id=CVE-2024-34158
Référence CVE CVE-2024-3596
https://www.cve.org/CVERecord?id=CVE-2024-3596
Référence CVE CVE-2024-37370
https://www.cve.org/CVERecord?id=CVE-2024-37370
Référence CVE CVE-2024-37371
https://www.cve.org/CVERecord?id=CVE-2024-37371
Référence CVE CVE-2024-4032
https://www.cve.org/CVERecord?id=CVE-2024-4032
Référence CVE CVE-2024-45336
https://www.cve.org/CVERecord?id=CVE-2024-45336
Référence CVE CVE-2024-45341
https://www.cve.org/CVERecord?id=CVE-2024-45341
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-4603
https://www.cve.org/CVERecord?id=CVE-2024-4603
Référence CVE CVE-2024-4741
https://www.cve.org/CVERecord?id=CVE-2024-4741
Référence CVE CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
Référence CVE CVE-2024-5535
https://www.cve.org/CVERecord?id=CVE-2024-5535
Référence CVE CVE-2024-5642
https://www.cve.org/CVERecord?id=CVE-2024-5642
Référence CVE CVE-2024-6119
https://www.cve.org/CVERecord?id=CVE-2024-6119
Référence CVE CVE-2024-6232
https://www.cve.org/CVERecord?id=CVE-2024-6232
Référence CVE CVE-2024-6923
https://www.cve.org/CVERecord?id=CVE-2024-6923
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0760Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-12133
Référence CVE CVE-2024-12243
https://www.cve.org/CVERecord?id=CVE-2024-12243
Référence CVE CVE-2024-12718
https://www.cve.org/CVERecord?id=CVE-2024-12718
Référence CVE CVE-2024-36114
https://www.cve.org/CVERecord?id=CVE-2024-36114
Référence CVE CVE-2024-4067
https://www.cve.org/CVERecord?id=CVE-2024-4067
Référence CVE CVE-2024-43799
https://www.cve.org/CVERecord?id=CVE-2024-43799
Référence CVE CVE-2024-43800
https://www.cve.org/CVERecord?id=CVE-2024-43800
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-45813
https://www.cve.org/CVERecord?id=CVE-2024-45813
Référence CVE CVE-2024-48948
https://www.cve.org/CVERecord?id=CVE-2024-48948
Référence CVE CVE-2024-48949
https://www.cve.org/CVERecord?id=CVE-2024-48949
Référence CVE CVE-2024-49766
https://www.cve.org/CVERecord?id=CVE-2024-49766
Référence CVE CVE-2024-49767
https://www.cve.org/CVERecord?id=CVE-2024-49767
Référence CVE CVE-2024-49828
https://www.cve.org/CVERecord?id=CVE-2024-49828
Référence CVE CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
Référence CVE CVE-2024-51473
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0651Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-21131
Référence CVE CVE-2024-21138
https://www.cve.org/CVERecord?id=CVE-2024-21138
Référence CVE CVE-2024-21140
https://www.cve.org/CVERecord?id=CVE-2024-21140
Référence CVE CVE-2024-21144
https://www.cve.org/CVERecord?id=CVE-2024-21144
Référence CVE CVE-2024-21145
https://www.cve.org/CVERecord?id=CVE-2024-21145
Référence CVE CVE-2024-21147
https://www.cve.org/CVERecord?id=CVE-2024-21147
Référence CVE CVE-2024-27267
https://www.cve.org/CVERecord?id=CVE-2024-27267
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-47081
https://www.cve.org/CVERecord?id=CVE-2024-47081
Référence CVE CVE-2024-49342
https://www.cve.org/CVERecord?id=CVE-2024-49342
Référence CVE CVE-2024-49343
https://www.cve.org/CVERecord?id=CVE-2024-49343
Référence CVE CVE-2024-50602
https://www.cve.org/CVERecord?id=CVE-2024-50602
Référence CVE CVE-2025-0755
https://www.cve.org/CVERecord?id=CVE-2025-0755
Référence CVE CVE-2025-24970
https://www.cve.org/CVERecord?id=CVE-2025-24970
Référence CVE CVE-2025-27607
https://www.cve.org/CVERecord?id=CVE-2025-27607
Référence CVE CVE-2025-30472
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0492Multiples vulnérabilités dans les produits Siemenss antérieures à V3.2
SIMATIC S7-1500 versions supérieures ou égales àV3.1.5 pour les vulnérabilités CVE-2021-41617, CVE-2023-4527, CVE-2023-4806, CVE-2023-4911, CVE-2023-5363, CVE-2023-6246, CVE-2023-6779, CVE-2023-6780, CVE-2023-28531, CVE-2023-38545, CVE-2023-38546, CVE-2023-44487, CVE-2023-46218, CVE-2023-46219, CVE-2023-48795, CVE-2023-51384, CVE-2023-51385, CVE-2023-52927, CVE-2024-2961, CVE-2024-6119, CVE-2024-6387, CVE-2024-12133, CVE-2024-12243, CVE-2024-24855, CVE-2024-26596, CVE-2024-28085, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602, CVE-2024-34397, CVE-2024-37370, CVE-2024-37371, CVE-2024-45490, CVE-2024-45491, CVE-2024-45492, CVE-2024-50246, CVE-2024-53166, CVE-2024-57977, CVE-2024-57996, CVE-2024-58005, CVE-2025-4373, CVE-2025-4598, CVE-2025-21701, CVE-2025-21702, CVE-2025-21712, CVE-2025-21724, CVE-2025-21728, CVE-2025-21745, CVE-2025-21756, CVE-2025-21758, CVE-2025-21765, CVE-2025-21766, CVE-2025-21767, CVE-2025-21795, CVE-2025-21796, CVE-2025-21848, CVE-2025-21862, CVE-2025-21864, CVE-2025-21865, CVE-2025-26465, CVE-2025-31115 et CVE-2025-46836.
Résumé
De multiples vulnérabilités ont été découvertes dans les produits Siemens. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilège
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0086Multiples vulnérabilités dans les produits IBMord?id=CVE-2024-10976
Référence CVE CVE-2024-25062
https://www.cve.org/CVERecord?id=CVE-2024-25062
Référence CVE CVE-2024-30203
https://www.cve.org/CVERecord?id=CVE-2024-30203
Référence CVE CVE-2024-30205
https://www.cve.org/CVERecord?id=CVE-2024-30205
Référence CVE CVE-2024-32007
https://www.cve.org/CVERecord?id=CVE-2024-32007
Référence CVE CVE-2024-39331
https://www.cve.org/CVERecord?id=CVE-2024-39331
Référence CVE CVE-2024-4032
https://www.cve.org/CVERecord?id=CVE-2024-4032
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-5535
https://www.cve.org/CVERecord?id=CVE-2024-5535
Référence CVE CVE-2024-5742
https://www.cve.org/CVERecord?id=CVE-2024-5742
Référence CVE CVE-2024-6232
https://www.cve.org/CVERecord?id=CVE-2024-6232
Référence CVE CVE-2024-6923
https://www.cve.org/CVERecord?id=CVE-2024-6923
Référence CVE CVE-2024-7254
https://www.cve.org/CVERecord?id=CVE-2024-7254
Gestion détaillée du document
le 31 janvier 2025
Version initiale
Alertes
Avis
Bulletins d’actualités
Mentions légales
Conditions générales
À propos
Contact
cyber.gouv.fr
service-public.fr
legifrance.gouv.fr
info.gouv.fr
franc
Official advisory ↗CERT-FR · French · CERTFR-2025-AVI-0018Multiples vulnérabilités dans les produits Juniper Networksd?id=CVE-2024-41055
Référence CVE CVE-2024-41073
https://www.cve.org/CVERecord?id=CVE-2024-41073
Référence CVE CVE-2024-41096
https://www.cve.org/CVERecord?id=CVE-2024-41096
Référence CVE CVE-2024-42082
https://www.cve.org/CVERecord?id=CVE-2024-42082
Référence CVE CVE-2024-42096
https://www.cve.org/CVERecord?id=CVE-2024-42096
Référence CVE CVE-2024-42102
https://www.cve.org/CVERecord?id=CVE-2024-42102
Référence CVE CVE-2024-42131
https://www.cve.org/CVERecord?id=CVE-2024-42131
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-6119
https://www.cve.org/CVERecord?id=CVE-2024-6119
Référence CVE CVE-2024-6387
https://www.cve.org/CVERecord?id=CVE-2024-6387
Référence CVE CVE-2025-21592
https://www.cve.org/CVERecord?id=CVE-2025-21592
Référence CVE CVE-2025-21593
https://www.cve.org/CVERecord?id=CVE-2025-21593
Référence CVE CVE-2025-21596
https://www.cve.org/CVERecord?id=CVE-2025-21596
Référence CVE CVE-2025-21598
https://www.cve.org/CVERecord?id=CVE-2025-21598
Référence CVE CVE-2025-21599
https://www.cve.org/CVERecord?id=CVE-2025-21599
Référence CVE CVE-2025-21600
https://www.cve.org/CVERecord?id=CVE-
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0958Multiples vulnérabilités dans les produits IBMd?id=CVE-2024-43800
Référence CVE CVE-2024-43824
https://www.cve.org/CVERecord?id=CVE-2024-43824
Référence CVE CVE-2024-43832
https://www.cve.org/CVERecord?id=CVE-2024-43832
Référence CVE CVE-2024-43833
https://www.cve.org/CVERecord?id=CVE-2024-43833
Référence CVE CVE-2024-43857
https://www.cve.org/CVERecord?id=CVE-2024-43857
Référence CVE CVE-2024-43858
https://www.cve.org/CVERecord?id=CVE-2024-43858
Référence CVE CVE-2024-45296
https://www.cve.org/CVERecord?id=CVE-2024-45296
Référence CVE CVE-2024-45490
https://www.cve.org/CVERecord?id=CVE-2024-45490
Référence CVE CVE-2024-45491
https://www.cve.org/CVERecord?id=CVE-2024-45491
Référence CVE CVE-2024-45492
https://www.cve.org/CVERecord?id=CVE-2024-45492
Référence CVE CVE-2024-45590
https://www.cve.org/CVERecord?id=CVE-2024-45590
Référence CVE CVE-2024-45801
https://www.cve.org/CVERecord?id=CVE-2024-45801
Référence CVE CVE-2024-46982
https://www.cve.org/CVERecord?id=CVE-2024-46982
Référence CVE CVE-2024-47764
https://www.cve.org/CVERecord?id=CVE-2024-47764
Référence CVE CVE-2024-47874
https://www.cve.org/CVERecord?id=CVE-2024-47874
Référence CVE CVE-2024-47875
https://www.cve.org/CVERecord?id=CVE-2024-47875
Référence CVE CVE-2024-5535
https://www.cve.org/CVERecord?id=CVE-2024-5535
Référence CVE CVE-2024-6119
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0807Multiples vulnérabilités dans Nessus Network MonitorDe multiples vulnérabilités ont été découvertes dans Nessus Network Monitor. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une injection de code indirecte à distance (XSS) et un problème de sécurité non spécifié par l'éditeur.
Official advisory ↗CERT-FR · French · CERTFR-2024-AVI-0771Multiples vulnérabilités dans les produits TenableDe multiples vulnérabilités ont été découvertes dans les produits Tenable. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.
Official advisory ↗JVN iPedia · Japanese · JVNDB-2024-007221libexpat project の libexpat における整数オーバーフローの脆弱性libexpat project の libexpat には、整数オーバーフローの脆弱性が存在します。
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0020Kwetsbaarheden verholpen in Oracle Database productenDe kwetsbaarheden bevinden zich in verschillende componenten van de Oracle Database, waaronder de Data Mining component en de Java VM. Deze kwetsbaarheden stellen laaggeprivilegieerde geauthenticeerde gebruikers in staat om het systeem te compromitteren, wat kan leiden tot ongeautoriseerde toegang en gegevensmanipulatie. De Java VM-kwetsbaarheid kan ook leiden tot ongeautoriseerde wijzigingen van gegevens.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0187Kwetsbaarheden verholpen in Siemens productenDe kwetsbaarheden stellen een kwaadwillende mogelijk in staat aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipulatie van gegevens
- Omzeilen van een beveiligingsmaatregel
- Omzeilen van authenticatie
- (Remote) code execution (root/admin rechten)
- (Remote) code execution (Gebruikersrechten)
- Toegang tot systeemgegevens
- Toegang tot gevoelige gegevens
- Spoofing
De kwaadwillende heeft hiervoor toegang nodig tot de productieomgeving. Het is goed gebruik een dergelijke omgeving niet publiek toegankelijk te hebben.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0027Kwetsbaarheden verholpen in Oracle Fusion MiddlewareDe kwetsbaarheden bevinden zich in verschillende Oracle producten, waaronder Oracle WebLogic Server versies 12.2.1.4.0 en 14.1.1.0.0, die het mogelijk maken voor ongeauthenticeerde kwaadwillenden om toegang te krijgen tot kritieke gegevens. Dit kan leiden tot ernstige gevolgen voor de vertrouwelijkheid, integriteit en beschikbaarheid van de systemen. De kwetsbaarheid in Oracle HTTP Server versie 12.2.1.4.0 stelt kwaadwillenden in staat om ongeautoriseerde toegang te verkrijgen, met een CVSS-score van 5.3, terwijl de kwetsbaarheid in WebLogic Server een CVSS-score van 9.8 heeft, wat wijst op een kritieke impact. Kwaadwillenden kunnen ook gebruik maken van kwetsbaarheden in Oracle Fusion Middleware en andere producten om Denial-of-Service (DoS) aanvallen uit te voeren.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0025Kwetsbaarheden verholpen in Oracle Financial ServicesDe kwetsbaarheden stellen ongeauthenticeerde aanvallers in staat om toegang te krijgen tot kritieke gegevens en de systeemintegriteit in gevaar te brengen. Specifieke kwetsbaarheden kunnen leiden tot compromittering van vertrouwelijkheid, integriteit en beschikbaarheid, met schadeclassificaties variërend van gemiddeld tot hoog. Sommige kwetsbaarheden kunnen op afstand worden uitgebuit zonder gebruikersinteractie, wat het risico op privilege-escalatie en denial-of-service vergroot.
Official advisory ↗NCSC-NL · Dutch · NCSC-2025-0021Kwetsbaarheden verholpen in Oracle CommunicationsDe kwetsbaarheden stellen ongeauthenticeerde kwaadwillenden in staat om Denial of Service (DoS) aanvallen uit te voeren of om ongeautoriseerde toegang tot gevoelige gegevens te verkrijgen. Specifieke versies, zoals 24.2.0 en 24.3.0 van de Cloud Native Core Network Function, zijn bijzonder kwetsbaar. Kwaadwillenden kunnen deze kwetsbaarheden misbruiken door speciaal geprepareerde HTTP-verzoeken te sturen naar het kwetsbare systeem.
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0417Kwetsbaarheden verholpen in Oracle Fusion MiddlewareEen kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipuleren van data
- Uitvoer van willekeurige code (Administratorrechten)
- Toegang tot gevoelige gegevens
Omdat deze kwetsbaarheden zich bevinden in diverse Middleware producten, is niet uit te sluiten dat applicaties, draaiende op platformen ondersteund door deze middleware ook kwetsbaar zijn, danwel gevoelig voor misbruik van deze kwetsbaarheden.
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0414Kwetsbaarheden verholpen in Oracle CommunicationsEen kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipuleren van gegevens
- Uitvoer van willekeurige code (Gebruikersrechten)
- Uitvoer van willekeurige code (Administratorrechten)
- Toegang tot gevoelige gegevens
Official advisory ↗NCSC-NL · Dutch · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database productenEen kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade:
- Denial-of-Service (DoS)
- Manipuleren van data
- Toegang tot gevoelige gegevens
Official advisory ↗