← Back

Oracle Optimization

oracle_optimization

Vendor: Usu • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Usu
1Oracle Optimization
Nov 21, 2024
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked....Show more
USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked. NOTE: this is not an Oracle Corporation product.Show less
1Usu
1Oracle Optimization
Nov 21, 2024
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation produ...Show more
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation product.Show less
1Usu
1Oracle Optimization
Nov 21, 2024
Apr 29, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer download. NOTE: this is not an Oracle Corporation product.
1Usu
1Oracle Optimization
Nov 21, 2024
Apr 29, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.