

APT28 FancyBear Group – Active IOCs
October 24, 2024
Google Chrome Zero-Day Vulnerability Exploited by Lazarus Group by Using Phony DeFi Game – Active IOCs
October 24, 2024
APT28 FancyBear Group – Active IOCs
October 24, 2024
Google Chrome Zero-Day Vulnerability Exploited by Lazarus Group by Using Phony DeFi Game – Active IOCs
October 24, 2024Severity
High
Analysis Summary
CVE-2024-21234 CVSS:7.5
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.
CVE-2024-21216 CVSS:9.8
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server.
CVE-2024-21215 CVSS:7.5
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebLogic Server.
CVE-2024-21214 CVSS:8.1
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query). Supported versions that are affected are 8.59, 8.60 and 8.61. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data.
CVE-2024-21195 CVSS:7.6
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Layout Templates). Supported versions that are affected are 7.0.0.0.0, 7.6.0.0.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as unauthorized update.
CVE-2024-21191 CVSS:7.6
Vulnerability in the Oracle Enterprise Manager Fusion Middleware Control product of Oracle Fusion Middleware (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Fusion Middleware Control. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manage.
CVE-2024-21190 CVSS:7.5
Vulnerability in the Oracle Global Lifecycle Management FMW Installer product of Oracle Fusion Middleware (component: Cloning). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFTP to compromise Oracle Global Lifecycle Management FMW Installer. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Global Lifecycle.
CVE-2024-21172 CVSS:9
Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.19.19, 5.6.25.8 and 5.6.26.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5. While the vulnerability is in Oracle Hospitality OPERA 5, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability.
Impact
- Gain Access
- Privilege Escalation
- Denial of Service
Indicators of Compromise
CVE
- CVE-2024-21234
- CVE-2024-21216
- CVE-2024-21215
- CVE-2024-21214
- CVE-2024-21195
- CVE-2024-21191
- CVE-2024-21190
- CVE-2024-21172
Affected Vendors
Affected Products
- Oracle Corporation Oracle WebLogic Server - 12.2.1.4.0 - 14.1.1.0.0
- Oracle Corporation PeopleSoft Enterprise PeopleTools - 8.59 - 8.60 - 8.61
- Oracle Corporation Oracle BI Publisher - 7.0.0.0.0 - 7.6.0.0.0 - 12.2.1.4.0
- Oracle Corporation Oracle Enterprise Manager Fusion Middleware Control - 12.2.1.4.0
- Oracle Corporation Oracle Global Lifecycle Management FMW Installer - 12.2.1.4.0
- Oracle Corporation Oracle Hospitality OPERA 5 - 5.6.19.19 - 5.6.25.8 - 5.6.26.4
Remediation
Refer to Oracle Critical Patch Update Advisory, upgrade or suggested workaround information.