-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512


   #####################################################
  ##  N C S C ~ B E V E I L I G I N G S A D V I E S  ##
 #####################################################

Titel           : Kwetsbaarheden verholpen in Oracle Communications
Advisory ID     : NCSC-2024-0414
Versie          : 1.00
Kans            : medium
CVE ID          : CVE-2021-37137, CVE-2022-2068, CVE-2022-2601,
                  CVE-2022-23437, CVE-2022-36760, CVE-2023-2953,
                  CVE-2023-3635, CVE-2023-4043, CVE-2023-5685,
                  CVE-2023-6597, CVE-2023-6816, CVE-2023-38408,
                  CVE-2023-43642, CVE-2023-46136, CVE-2023-48795,
                  CVE-2023-51775, CVE-2023-52428, CVE-2024-0450,
                  CVE-2024-2398, CVE-2024-4577, CVE-2024-4603,
                  CVE-2024-5585, CVE-2024-5971, CVE-2024-6162,
                  CVE-2024-6387, CVE-2024-7254, CVE-2024-7264,
                  CVE-2024-22020, CVE-2024-22201, CVE-2024-22257,
                  CVE-2024-22262, CVE-2024-23672, CVE-2024-23807,
                  CVE-2024-24549, CVE-2024-25062, CVE-2024-25638,
                  CVE-2024-26308, CVE-2024-28182, CVE-2024-28849,
                  CVE-2024-29025, CVE-2024-29133, CVE-2024-29736,
                  CVE-2024-29857, CVE-2024-30251, CVE-2024-31080,
                  CVE-2024-31744, CVE-2024-32760, CVE-2024-33602,
                  CVE-2024-34750, CVE-2024-37371, CVE-2024-37891,
                  CVE-2024-38816, CVE-2024-39689, CVE-2024-40898,
                  CVE-2024-41817, CVE-2024-43044, CVE-2024-45492
                  (Details over de kwetsbaarheden kunt u vinden op
                   de Mitre website: https://cve.mitre.org/cve/)
Schade          : high
                  Improper Check for Unusual or Exceptional Conditions
                  Out-of-bounds Read
                  Improper Neutralization of Argument Delimiters in a
                  Command ('Argument Injection')
                  Inconsistent Interpretation of HTTP Requests ('HTTP
                  Request/Response Smuggling')
                  Signal Handler Race Condition
                  Improper Restriction of Operations within the Bounds
                  of a Memory Buffer
                  UNIX Symbolic Link (Symlink) Following
                  Improper Neutralization of Special Elements used in a
                  Command ('Command Injection')
                  Unchecked Input for Loop Condition
                  Uncaught Exception
                  Use After Free
                  Improper Input Validation
                  Heap-based Buffer Overflow
                  Missing Release of Resource after Effective Lifetime
                  Uncontrolled Search Path Element
                  NULL Pointer Dereference
                  Out-of-bounds Write
                  Signed to Unsigned Conversion Error
                  Improper Neutralization of Special Elements used in an
                  OS Command ('OS Command Injection')
                  Uncontrolled Resource Consumption
                  Detection of Error Condition Without Action
                  Exposure of Sensitive Information to an Unauthorized
                  Actor
                  Excessive Iteration
                  Improper Check or Handling of Exceptional Conditions
                  Improper Limitation of a Pathname to a Restricted
                  Directory ('Path Traversal')
                  Improper Control of Generation of Code ('Code
                  Injection')
                  Improper Handling of Length Parameter Inconsistency
                  Buffer Over-read
                  Allocation of Resources Without Limits or Throttling
                  Loop with Unreachable Exit Condition ('Infinite Loop')
                  Improper Handling of Exceptional Conditions
                  Integer Overflow or Wraparound
                  Acceptance of Extraneous Untrusted Data With Trusted
                  Data
                  Improper Access Control
                  Improper Encoding or Escaping of Output
                  URL Redirection to Untrusted Site ('Open Redirect')
                  Truncation of Security-relevant Information
                  Improper Resource Shutdown or Release
                  Missing Release of Memory after Effective Lifetime
                  Insufficient Verification of Data Authenticity
                  Server-Side Request Forgery (SSRF)
                  Multiple Interpretations of UI Input
                  Return of Pointer Value Outside of Expected Range
                  Incorrect Resource Transfer Between Spheres
                  Uncontrolled Recursion
                  Inefficient Algorithmic Complexity
                  Incomplete Cleanup
                  Asymmetric Resource Consumption (Amplification)
                  Concurrent Execution using Shared Resource with
                  Improper Synchronization ('Race Condition')
Uitgiftedatum   : 20241017
Toepassing      : oracle communications
                  oracle communications__10.4.0.4
                  oracle communications___23.4.2
                  oracle communications___23.4.3
                  oracle communications___23.4.4
                  oracle communications___23.4.5
                  oracle communications___23.4.6
                  oracle communications___24.2.0
                  oracle communications___7.2.1.0.0
                  oracle communications___8.6.0.6
                  oracle communications___8.6.0.8
                  oracle communications___9.0.2
                  oracle communications___9.0.3
                  oracle communications___9.1.1.8.0
                  oracle communications_applications
                  oracle communications_applications___12.0.6.0.0
                  oracle communications_applications___5.5.22
                  oracle communications_applications___6.0.3
                  oracle communications_applications___6.0.4
                  oracle communications_applications___6.0.5
                  oracle communications_asap
                  oracle communications_billing_and_revenue_management
                  oracle
                  communications_billing_and_revenue_management__-
                  _elastic_charging_engine
                  oracle communications_brm_-_elastic_charging_engine
                  oracle communications_calendar_server
                  oracle
                  communications_cloud_native_configuration_console
                  oracle
                  communications_cloud_native_core_automated_test_suite
                  oracle communications_cloud_native_core_binding_suppor
                  t_function
                  oracle communications_cloud_native_core_certificate_ma
                  nagement
                  oracle communications_cloud_native_core_console
                  oracle communications_cloud_native_core_dbtier
                  oracle communications_cloud_native_core_network_data_a
                  nalytics_function
                  oracle communications_cloud_native_core_network_exposu
                  re_function
                  oracle communications_cloud_native_core_network_functi
                  on_cloud_native_environment
                  oracle communications_cloud_native_core_network_reposi
                  tory_function
                  oracle communications_cloud_native_core_network_slice_
                  selection_function
                  oracle communications_cloud_native_core_policy
                  oracle communications_cloud_native_core_security_edge_
                  protection_proxy
                  oracle communications_cloud_native_core_service_commun
                  ication_proxy
                  oracle communications_cloud_native_core_unified_data_r
                  epository
                  oracle communications_contacts_server
                  oracle communications_converged_application_server
                  oracle communications_converged_application_server_-
                  _service_controller
                  oracle communications_converged_charging_system
                  oracle communications_convergence
                  oracle communications_convergent_charging_controller
                  oracle communications_core_session_manager
                  oracle communications_data_model
                  oracle communications_design_studio
                  oracle communications_diameter_intelligence_hub
                  oracle communications_diameter_signaling_router
                  oracle communications_eagle_application_processor
                  oracle communications_eagle_element_management_system
                  oracle communications_eagle_ftp_table_base_retrieval
                  oracle communications_eagle_lnp_application_processor
                  oracle communications_eagle_software
                  oracle communications_elastic_charging_engine
                  oracle communications_element_manager
                  oracle communications_evolved_communications_applicati
                  on_server
                  oracle communications_fraud_monitor
                  oracle communications_instant_messaging_server
                  oracle communications_interactive_session_recorder
                  oracle communications_ip_service_activator
                  oracle communications_lsms
                  oracle communications_messaging_server
                  oracle communications_metasolv_solution
                  oracle communications_network_analytics_data_director
                  oracle communications_network_charging_and_control
                  oracle communications_network_integrity
                  oracle communications_offline_mediation_controller
                  oracle communications_operations_monitor
                  oracle communications_order_and_service_management
                  oracle communications_performance_intelligence
                  oracle communications_performance_intelligence_center
                  oracle communications_performance_intelligence_center_
                  _pic__software
                  oracle communications_policy_management
                  oracle communications_pricing_design_center
                  oracle communications_service_catalog_and_design
                  oracle communications_services_gatekeeper
                  oracle communications_session_border_controller
                  oracle communications_session_report_manager
                  oracle communications_session_route_manager
                  oracle communications_session_router
                  oracle communications_subscriber-aware_load_balancer
                  oracle communications_unified_assurance
                  oracle communications_unified_inventory_management
                  oracle communications_unified_session_manager
                  oracle communications_user_data_repository
                  oracle communications_webrtc_session_controller
Versie(s)       :
Platform(s)     :

Beschrijving
   Oracle heeft kwetsbaarheden verholpen in diverse Communications
   producten en systemen.

   Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit
   te voeren die kunnen leiden tot de volgende categorieën schade:
   - Denial-of-Service (DoS)
   - Manipuleren van gegevens
   - Uitvoer van willekeurige code (Gebruikersrechten)
   - Uitvoer van willekeurige code (Administratorrechten)
   - Toegang tot gevoelige gegevens

Mogelijke oplossingen
   Oracle heeft updates uitgebracht om de kwetsbaarheden te verhelpen.
   Zie bijgevoegde referenties voor meer informatie.

   Referenties:
      Reference - cveprojectv5; hkcert; nvd; oracle; redhat
      https://www.oracle.com/security-alerts/cpuoct2024.html

Vrijwaringsverklaring
   Door gebruik van deze security advisory gaat u akkoord met de
   navolgende voorwaarden. Ondanks dat het NCSC de grootst mogelijke
   zorg heeft betracht bij de samenstelling van dit beveiligingsadvies,
   kan het NCSC niet instaan voor de volledigheid, juistheid of
   (voortdurende) actualiteit van dit beveiligingsadvies. De informatie
   in dit beveiligingsadvies is uitsluitend bedoeld als algemene
   informatie voor professionele partijen. Aan de informatie in dit
   beveiligingsadvies kunnen geen rechten worden ontleend. Het NCSC
   en de Staat zijn niet aansprakelijk voor enige schade ten gevolge
   van het gebruik of de onmogelijkheid van het gebruik van dit
   beveiligingsadvies, waaronder begrepen schade ten gevolge van de
   onjuistheid of onvolledigheid van de informatie in dit
   beveiligingsadvies. Op dit beveiligingsadvies is Nederlands recht
   van toepassing. Alle geschillen in verband met en/of voortvloeiend
   uit dit beveiligingsadvies zullen worden voorgelegd aan de exclusief
   bevoegde rechter te Den Haag. Deze rechtskeuze geldt tevens voor de
   voorzieningenrechter in kort geding.

-----BEGIN PGP SIGNATURE-----

wsDzBAEBCgAdBQJnEQ6GFiEEbfBszMuom42mJgp8sECQZ3v2JPIACgkQsECQZ3v2
JPIAtAwAqosZW9uPhBFOxjbCQxLG6w+vqn7tsV0NdFc7OMyi+c9n0VlMw8oeH6xj
8qAD9bBOCRWwZsrIes/Is/W6V5smkpglBdy/0iRkaX5/bHq8D7C1rGcEPft4xPyX
iAq2IYuxcHES0Ex7H/vuBUZHzc8k/OP4hQxnQZayGJoLafCX+sE2UDFeFfGbM8ZJ
YA4SPeWPvuLRGTRbtAztV7Sye/mdD1nmN3JTZscEXx8jPSETovOE9gppF4Hb5n2q
AxGSrNuft/drRUxAUUKxQ6y6+WqDLvJf2baodPeuuYV8zQBF/NZy67ZxMI1U+HVs
WxjkX0j6xGtcKE3h+TcDJVsZ7Xb1QByRD23J/532LLCxNonQ12vFGel4mQrEixwT
Tp7ZkYoT6zGVIwFfh3skDcRyARMyKEOPqvmeKUs3Q0VlEMi5CAwhO0LH0QPdW5qK
i30dPa5eBrfdFoz0FVMl6DVR+7cmXzkaeUQXLEkj+33gNNWMVwSfZxXL5A6glDH6
GcMjB7ui
=JAGw
-----END PGP SIGNATURE-----