CVE-2018-2643
published 2018-01-18CVE-2018-2643: Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Case Selection). Supported versions that are affected…
PriorityP434medium6.4CVSS 3.0
AVNACLPRLUINSCCLILAN
EPSS
0.74%
50.3th percentile
Vulnerability in the Oracle Argus Safety component of Oracle Health Sciences Applications (subcomponent: Case Selection). Supported versions that are affected are 7.x and 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. While the vulnerability is in Oracle Argus Safety, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Argus Safety accessible data as well as unauthorized read access to a subset of Oracle Argus Safety accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle_corporation | argus_safety | — | — |
| oracle_corporation | argus_safety | — | — |
CVSS provenance
nvdv3.06.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-11499 libsass: Use-after-free vulnerability in sass_context.cpp:handle_error() can lead to denial of service or other unspecified impact
bugzilla·2018-05-28·CVSS 9.8
CVE-2018-11499 [CRITICAL] CVE-2018-11499 libsass: Use-after-free vulnerability in sass_context.cpp:handle_error() can lead to denial of service or other unspecified impact
CVE-2018-11499 libsass: Use-after-free vulnerability in sass_context.cpp:handle_error() can lead to denial of service or other unspecified impact
A use-after-free vulnerability exists in handle_error() in sass_context.cpp in LibSass 3.4.x and 3.5.x through 3.5.4 that could be leveraged to cause a denial of service (application crash) or possibly unspecified other impact.
Upstream bug:
https://github.com/sass/libsass/issues/2643
Discussion:
Created libsass tracking bugs for this issue:
Affects: fedora-all [bug 1583183]
---
Upstream patch:
https://github.com/sass/libsass/pull/2755
Bugzilla
CVE-2018-1114 undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service
bugzilla·2018-04-30·CVSS 6.5
CVE-2018-1114 [MEDIUM] CVE-2018-1114 undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service
CVE-2018-1114 undertow: File descriptor leak caused by JarURLConnection.getLastModified() allows attacker to cause a denial of service
Undertow has a file handler leak vulnerability caused by JarURLConnection.getLastModified(). A remote attacker could exploit this to cause a denial of service.
External References:
https://issues.jboss.org/browse/UNDERTOW-1338
https://bugs.openjdk.java.net/browse/JDK-6956385
Discussion:
Created undertow tracking bugs for this issue:
Affects: fedora-all [bug 1573047]
---
This issue has been addressed in the following products:
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
Via RHSA-2018:2643 https://access.redhat.com/errata/RHSA-2018:2643
---
This issue has been addressed in the following products:
Red Hat JBoss Fuse
Via RHSA-2018:266
2018-01-18
Published