

Rewterz Threat Alert – STOP (DJVU) Ransomware – Active IOCs
March 29, 2023
Rewterz Threat Advisory – Multiple Apache OperOffice Vulnerabilities
March 29, 2023
Rewterz Threat Alert – STOP (DJVU) Ransomware – Active IOCs
March 29, 2023
Rewterz Threat Advisory – Multiple Apache OperOffice Vulnerabilities
March 29, 2023Severity
Medium
Analysis Summary
CVE-2023-25197 CVSS:5.4
Apache Fineract is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2023-25196 CVSS:5.4
Apache Fineract is vulnerable to SQL injection. A remote authenticated attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVE-2023-25195 CVSS:6.5
Apache Fineract is vulnerable to server-side request forgery, caused by a flaw in the Template Handler. By sending a specially crafted request, an attacker could exploit this vulnerability to conduct SSRF attack.
Impact
- Gain Access
- Data Manipulation
Indicators Of Compromise
CVE
- CVE-2023-25197
- CVE-2023-25196
- CVE-2023-25195
Affected Vendors
Apache
Affected Products
- Apache Fineract 1.4.0
- Apache Fineract 1.8.2
Remediation
Upgrade to the latest version of Apache Fineract, available from the Apache Website.