SB20221018120 - Multiple vulnerabilities in Enterprise Manager Base Platform



SB20221018120 - Multiple vulnerabilities in Enterprise Manager Base Platform

Published: October 18, 2022

Security Bulletin ID SB20221018120
Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 33% Medium 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 secuirty vulnerabilities.


1) Deserialization of Untrusted Data (CVE-ID: CVE-2021-4104)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to insecure input validation when processing serialized data in JMSAppender, when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution.

Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default.


2) Improper input validation (CVE-ID: CVE-2022-21623)

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The vulnerability exists due to improper input validation within the Application Config Console component in Enterprise Manager Base Platform. A remote non-authenticated attacker can exploit this vulnerability to manipulate data.


3) Improper input validation (CVE-ID: CVE-2018-1285)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The vulnerability exists due to improper input validation within the Simphony Server (Apache log4net) component in Oracle Hospitality Simphony. A remote non-authenticated attacker can exploit this vulnerability to execute arbitrary code.


Remediation

Install update from vendor's website.