CVE-2019-2538
published 2019-01-16CVE-2019-2538: Vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware (subcomponent: MFT Runtime Server). Supported versions that are…
PriorityP338high7.1CVSS 3.0
AVNACLPRLUINSUCLIHAN
EPSS
1.12%
62.4th percentile
Vulnerability in the Oracle Managed File Transfer component of Oracle Fusion Middleware (subcomponent: MFT Runtime Server). Supported versions that are affected are 19.1.0.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as unauthorized read access to a subset of Oracle Managed File Transfer accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | managed_file_transfer | — | — |
| oracle | managed_file_transfer | — | — |
| oracle_corporation | managed_file_transfer | — | — |
| oracle_corporation | managed_file_transfer | — | — |
CVSS provenance
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys
bugzilla·2019-01-11·CVSS 5.5
CVE-2018-16889 [MEDIUM] CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys
CVE-2018-16889 ceph: debug logging for v4 auth does not sanitize encryption keys
Ceph does not properly sanitize encryption keys in debug logging for v4 auth. This results in the leaking of encryption key information in log files via plaintext.
Upstream Patch:
https://github.com/ceph/ceph/pull/25881/commits
Upstream Bug:
http://tracker.ceph.com/issues/37847
Discussion:
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1665335]
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3.3
Via RHSA-2019:2538 https://access.redhat.com/errata/RHSA-2019:2538
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3 for Red Hat Enterprise Linux 7
Via RHSA-2019:2541 https://access.redhat.com/errata/RHSA-2019:254
Bugzilla
CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase
bugzilla·2018-10-30·CVSS 6.5
CVE-2018-16846 [MEDIUM] CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase
CVE-2018-16846 ceph: ListBucket max-keys has no defined limit in the RGW codebase
RGW S3 listing operations provided a way for authenticated users to cause a denial of service against OMAPs holding bucket indices.
References:
http://tracker.ceph.com/issues/35994
Discussion:
External References:
https://ceph.com/releases/13-2-4-mimic-released/
---
Created ceph tracking bugs for this issue:
Affects: fedora-all [bug 1665973]
---
upstream fix
https://github.com/ceph/ceph/commit/ab29bed2fc9f961fe895de1086a8208e21ddaddc
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3.3
Via RHSA-2019:2538 https://access.redhat.com/errata/RHSA-2019:2538
---
This issue has been addressed in the following products:
Red Hat Ceph Storage 3 for Red Hat Enterprise L
2019-01-16
Published