-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ##################################################### ## N C S C ~ B E V E I L I G I N G S A D V I E S ## ##################################################### Titel : Kwetsbaarheden verholpen in Oracle Communications Advisory ID : NCSC-2026-0309 Versie : 1.00 Kans : medium CVE ID : CVE-2025-13151, CVE-2026-4176, CVE-2026-4800, CVE-2026-5795, CVE-2026-29167, CVE-2026-42587, CVE-2026-42779, CVE-2026-55956, CVE-2026-59084, CVE-2026-71142, CVE-2026-71143 (Details over de kwetsbaarheden kunt u vinden op de Mitre website: https://cve.mitre.org/cve/) Schade : high OWASP Top Ten 2013 Category A9 - Using Components with Known Vulnerabilities OWASP Top Ten 2017 Category A9 - Using Components with Known Vulnerabilities Insufficient Technical Documentation Use of Unmaintained Third Party Components CISQ Quality Measures (2016) - Security Dependency on Vulnerable Third-Party Component Improper Neutralization of Special Elements used in a Command ('Command Injection') Improper Control of Generation of Code ('Code Injection') Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Sensitive Information in Resource Not Removed Before Reuse Improper Authorization Improper Authentication Uncontrolled Resource Consumption Use After Free Deserialization of Untrusted Data Incorrect Behavior Order: Authorization Before Parsing and Canonicalization Allocation of Resources Without Limits or Throttling Out-of-bounds Write Uitgiftedatum : 20260819 Toepassing : Oracle Oracle Communications Oracle Oracle Communications BRM - Elastic Charging Engine Oracle Oracle Communications Billing and Revenue Management Oracle Oracle Communications Cloud Native Core Binding Support Function Oracle Oracle Communications Cloud Native Core DBTier Oracle Oracle Communications Cloud Native Core Network Exposure Function Oracle Oracle Communications Cloud Native Core Network Repository Function Oracle Oracle Communications Cloud Native Core Network Slice Selection Function Oracle Oracle Communications Cloud Native Core Policy Oracle Oracle Communications Cloud Native Core Security Edge Protection Proxy Oracle Oracle Communications Cloud Native Core Service Communication Proxy Oracle Oracle Communications Cloud Native Core Unified Data Repository Oracle Oracle Communications Network Analytics Data Director Oracle Oracle Communications Network Charging and Control Oracle Oracle Communications Network Integrity Oracle Oracle Communications Order and Service Management Oracle Oracle Communications Service Catalog and Design Oracle Oracle Communications Unified Assurance Oracle Oracle Communications Unified Inventory Management Versie(s) : Platform(s) : Beschrijving Oracle heeft kwetsbaarheden verholpen in verschillende Communications-modules, waaronder Oracle Communications Cloud Native Core Network Exposure Function, Oracle Commerce Guided Search en Oracle Communications Unified Inventory Management De kwetsbaarheden betreffen onder andere stack-based buffer overflows, onjuiste validatie van input, prototype pollution, improper authorization, use-after-free, deserialization filter bypass, en onvoldoende toegangscontrole. Aanvallers kunnen deze kwetsbaarheden misbruiken om onder meer Denial of Service (DoS) te veroorzaken, ongeautoriseerde toegang te verkrijgen, gevoelige data te wijzigen of in te zien, arbitrary code execution uit te voeren, en volledige systeemcompromittering te bereiken. Specifiek kunnen sommige kwetsbaarheden leiden tot privilege escalatie, bypass van authenticatie, en remote code execution zonder authenticatie. De kwetsbaarheden zijn aanwezig in diverse versies van de genoemde producten en modules, waarbij sommige fixes reeds zijn uitgebracht in specifieke versies. Controleer daarom of de specifieke kwetsbaarheden van toepassing zijn op het eigen systeem. Mogelijke oplossingen Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen. Het wordt aanbevolen om de meest recente versies van de betreffende producten te installeren, zoals Oracle Communications Cloud Native Core Network Exposure Function versie 24.2.1 en hoger, Oracle Commerce Guided Search 11.4.0 en hoger, en de updates voor Oracle Communications Unified Inventory Management vanaf versie 8.0.2. Daarnaast zijn er patches beschikbaar voor de overige genoemde producten en modules. Zie bijgevoegde referenties voor meer informatie. Referenties: Reference https://www.oracle.com/security-alerts/cspuaug2026.html Vrijwaringsverklaring Door gebruik van deze security advisory gaat u akkoord met de navolgende voorwaarden. Ondanks dat het NCSC de grootst mogelijke zorg heeft betracht bij de samenstelling van dit beveiligingsadvies, kan het NCSC niet instaan voor de volledigheid, juistheid of (voortdurende) actualiteit van dit beveiligingsadvies. De informatie in dit beveiligingsadvies is uitsluitend bedoeld als algemene informatie voor professionele partijen. Aan de informatie in dit beveiligingsadvies kunnen geen rechten worden ontleend. Het NCSC en de Staat zijn niet aansprakelijk voor enige schade ten gevolge van het gebruik of de onmogelijkheid van het gebruik van dit beveiligingsadvies, waaronder begrepen schade ten gevolge van de onjuistheid of onvolledigheid van de informatie in dit beveiligingsadvies. Op dit beveiligingsadvies is Nederlands recht van toepassing. Alle geschillen in verband met en/of voortvloeiend uit dit beveiligingsadvies zullen worden voorgelegd aan de exclusief bevoegde rechter te Den Haag. Deze rechtskeuze geldt tevens voor de voorzieningenrechter in kort geding. -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEGSwziqblmmRNtImqgupWoL0ZhGEFAmqFexEACgkQgupWoL0Z hGEyBQv9HzWUilF/5HbKCAsienNElpRCN+UTNa0LBcc1tpKhddNAEf3dn8ETN5fJ U4YrjEpiOuYAt5mUCoQ9X6boax0twui6xaV3gJqTiUB1NHaFfeP3MxXTxk9CCYnO uaqSjrjCjsX4J4EZOFdBpucypc4COQti60uSIdCRzQ/MQcV94rO/2SgEBLFiJtxT uAVvyxjsIomQOm2N57DtWRzsbWOIG5IyFOYVYSWfG2ZnChzguCWf3N6JvSdZ0d5g Da74aVYD/KJ26IfOLpmtRHML34MI/+3BndTI4IrQ8epeMsf0lEt0VmEt3SPOu9hC Uf5iiveO/o/71NNsUc7lsfzChKlzKNilIsX0d5T4XhMhFhtjbAS+pylYY6HApoVo wNsBJV9P6hTwsQBLzUgf3rZL34ORw/aNaKX6DoNGOokZPUfGCpJecge+ijg8oQBP smJKZNPjw6WW2WEMMUhoGpV0RklQ5RAiuVEdDkfhB5grNY4OsS1kEgLH/hWiclq9 MA7AwLzw =3HV/ -----END PGP SIGNATURE-----