ZDI-23-175: Oracle WebRTC Session Controller parseCert Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle WebRTC Session Controller. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Oracle WebRTC Session Controller
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-175?
The severity of ZDI-23-175 is critical due to its potential to allow remote code execution.
2
How do I fix ZDI-23-175?
To fix ZDI-23-175, apply the latest security patch provided by Oracle for the WebRTC Session Controller.
3
What impact does ZDI-23-175 have on affected systems?
ZDI-23-175 can allow remote attackers to execute arbitrary code, leading to possible system compromise.
4
Is authentication required to exploit ZDI-23-175?
No, authentication is not required to exploit ZDI-23-175, making it particularly dangerous.
5
Which software is affected by ZDI-23-175?
ZDI-23-175 affects installations of Oracle WebRTC Session Controller.