CVE-2018-2691
published 2018-01-18CVE-2018-2691: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Proxy User Delegation). Supported versions that are affected…
PriorityP431medium5.4CVSS 3.0
AVNACLPRLUINSUCLILAN
EPSS
0.89%
55.2th percentile
Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Proxy User Delegation). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle User Management accessible data as well as unauthorized read access to a subset of Oracle User Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | user_management | — | — |
| oracle | user_management | — | — |
| oracle | user_management | — | — |
| oracle | user_management | — | — |
| oracle | user_management | — | — |
| oracle | user_management | — | — |
| oracle_corporation | user_management | — | — |
| oracle_corporation | user_management | — | — |
| oracle_corporation | user_management | — | — |
| oracle_corporation | user_management | — | — |
| oracle_corporation | user_management | — | — |
| oracle_corporation | user_management | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-1010083 python-flask: unexpected memory usage can lead to denial of service via crafted encoded JSON data
bugzilla·2020-10-13·CVSS 7.5
CVE-2019-1010083 [HIGH] CVE-2019-1010083 python-flask: unexpected memory usage can lead to denial of service via crafted encoded JSON data
CVE-2019-1010083 python-flask: unexpected memory usage can lead to denial of service via crafted encoded JSON data
The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this may overlap CVE-2018-1000656.
Reference:
https://www.palletsprojects.com/blog/flask-1-0-released/
Discussion:
Created python-flask tracking bugs for this issue:
Affects: epel-6 [bug 1888008]
---
External References:
https://palletsprojects.com/blog/flask-1-0-released/
https://snyk.io/vuln/SNYK-PYTHON-FLASK-451637
---
Upstream PR: https://github.com/pallets/flask/pull/2691
Upstream PR backport: https://github.com/pallets/flask/pull/2695
---
Red Hat Quay is using Flask 1.1.
Bugzilla
CVE-2018-1000656 python-flask: Denial of Service via crafted JSON file
bugzilla·2018-08-28·CVSS 7.5
CVE-2018-1000656 [HIGH] CVE-2018-1000656 python-flask: Denial of Service via crafted JSON file
CVE-2018-1000656 python-flask: Denial of Service via crafted JSON file
A flaw was found in The Pallets Project flask version Before 0.12.3. An Improper Input Validation vulnerability in flask that can result in a large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding.
References:
https://github.com/pallets/flask/pull/2691
Discussion:
Created python-flask tracking bugs for this issue:
Affects: fedora-all [bug 1623179]
---
Statement:
This issue affects the versions of python-flask as shipped with Red Hat Enterprise Linux 7.
Although Red Hat Satellite 6 contains the vulnerable component, the former is not affected due to python-flask only receiving JSON data created by other Red H
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102647http://www.securitytracker.com/id/1040201http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102647http://www.securitytracker.com/id/1040201
2018-01-18
Published