CVE-2022-21404
published 2022-04-19CVE-2022-21404: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions that are affected are 1.4.10 and…
PriorityP352high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
1.91%
78.3th percentile
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions that are affected are 1.4.10 and 2.0.0-RC1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_visual_studio_2022_version_17.4 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.6 | — | — |
| msrc | microsoft_visual_studio_2022_version_17.8 | — | — |
| msrc | net_6.0 | — | — |
| msrc | net_7.0 | — | — |
| msrc | net_8.0 | — | — |
| oracle | helidon | — | — |
| oracle | helidon | — | — |
| oracle_corporation | helidon | — | — |
| oracle_corporation | helidon | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_oracle8.1HIGH
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3w6-rw4q-h3px: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer)
ghsa_unreviewed·2022-04-20
CVE-2022-21404 [HIGH] GHSA-m3w6-rw4q-h3px: Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer)
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Reactive WebServer). Supported versions that are affected are 1.4.10 and 2.0.0-RC1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon. Successful attacks of this vulnerability can result in takeover of Helidon. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Microsoft
.NET Denial of Service Vulnerability
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2024-21404 [HIGH] CWE-476 .NET Denial of Service Vulnerability
.NET Denial of Service Vulnerability
.NET: .NET
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://dotnet.microsoft.com/download/dotnet/6.0
Reference: https://support.microsoft.com/help/5035119
Reference: https://dotnet.microsoft.com/en-us/download/dotnet/7.0
Reference: https://support.microsoft.com/help/5035120
Reference: https://dotnet.microsoft.com/en-us/download/dotnet/8.0
Reference: https://support.microsoft.com/help/5035121
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.4
Reference: https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Re
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Reactive WebServer — CVE-2022-21404
vendor_oracle·2022-04-15·CVSS 8.1
CVE-2022-21404 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Reactive WebServer — CVE-2022-21404
Oracle Oracle Fusion Middleware Risk Matrix: Reactive WebServer vulnerability
CVE: CVE-2022-21404
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
No detection rules found.
No public exploits indexed.
2022-04-19
Published