CVE-2023-21839 — Oracle WebLogic Server Unspecified Vulnerability
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
VulnWatch اطلاعات آسیبپذیری، امتیازها، نسخههای درگیر، راهکارها و دستورهای منتشرشده را از منابعی که در سامانه معرفی شدهاند گردآوری و برای دسترسی سادهتر نمایش میدهد. VulnWatch تولیدکننده یا مرجع اصلی این اطلاعات نیست.
ممکن است اطلاعات یک منبع ناقص، با تأخیر، تغییرکرده یا متناسب با محیط شما نباشد. VulnWatch صحت، کاملبودن، بهروز بودن یا نتیجه اجرای اطلاعات و دستورهای استخراجشده را تضمین نمیکند و مسئولیتی در قبال تصمیم، تغییر، اختلال یا خسارتی که صرفاً بر پایه این اطلاعات انجام شود نمیپذیرد.
پیش از نصب بهروزرسانی، اجرای دستور، تغییر تنظیمات یا هر اقدام عملیاتی، منبع اصلی را باز کنید، نسخه و محصول خود را تطبیق دهید، از اطلاعات مهم نسخه پشتیبان داشته باشید و تغییر را در محیط مناسب ارزیابی کنید.
آسیبپذیریها را بر اساس دستهبندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
Product issue: #EXTCERT-3028 "Postfix strict rules are not applied automatically and are removed in the update process"
Product issues: #PPP-49179 "The outdated PHP handlers (versions 5.6 and 7.0) no longer contain custom upload_tmp_dir as their values."
Hosting settings management permission is disabled in the respective Service Plan / Subscription settings.
Applicable to: Plesk for Linux Plesk for Windows Question How to disable specific ModSecurity rules for a domain or server-wide? Answer Note: Not all rules can be disabled due to the MODSEC-274 bug in ModSecurity. Disabling rules for a domain Log in to Plesk. Go to Domains > example.com > Web Application Firewall (ModSecurity). Note: The…
Applicable to: Plesk for Linux Plesk for Windows Question How to disable ModSecurity in Plesk? Answer Server-wide level: via Plesk UI Log into Plesk. Go to Tools & Settings > Web Application Firewall (ModSecurity) page. Set Web application firewall mode to Off and press OK button. via CLI Connect to the server via SSH or RDP. Disable…
Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.
Oracle Fusion Middleware Access Manager allows an unauthenticated attacker with network access via HTTP to takeover the Access Manager product.
The 404 error occurs when ModSecurity is unable to access the DBM files, or if the files do not exist.
Oracle WebLogic Server contains an unspecified vulnerability which can allow an unauthenticated attacker with T3 network access to compromise the server.
Question How do I change Security Measures options within the WP Toolkit interface? Procedure First, access the Security Measures UI like so: Log in to the user's cPanel account. Click on Domains / WordPress Management. Click the Security button at the top of the page. Click the > button to the right of the domain in the Details column. Select the…
Question How to enable Content-Security-Policy and Permissions-Policy Apache headers for all websites? Answer You may want to enable the Content-Security-Policy and Permissions-Policy headers to increase site security. This article provides the procedure to add these headers to the Apache configuration. Note: The following instructions assume you already…
Unspecified vulnerability in the Java Runtime Environment (JRE) in Java SE component allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors.
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware allows remote attackers to affect confidentiality, integrity, and availability via Unknown vectors related to Designer.
A vulnerability in the way Java restricts the permissions of Java applets could allow an attacker to execute commands on a vulnerable system.
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle allows remote attackers to bypass the Java security sandbox.
Unspecified vulnerability in hotspot for Java Runtime Environment (JRE) allows remote attackers to affect integrity.
Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.
When two passdb configuration entries exist in Dovecot configuration, which have the same driver and args settings, the incorrect username_filter and mechanism settings can be applied to passdb definitions. These incorrectly applied settings can lead to an unintended security configuration and can permit privilege escalation with certain configurations…
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors