ZDI-CAN-18862: ZDI-23-175: Oracle WebRTC Session Controller parseCert Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Feb 24, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle WebRTC Session Controller. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
Oracle WebRTC Session Controller
Event History
Feb 24, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-18862?
The severity of ZDI-CAN-18862 is critical due to its potential for remote code execution without authentication.
2
How do I fix ZDI-CAN-18862?
To fix ZDI-CAN-18862, apply the latest patches and updates provided by Oracle for the WebRTC Session Controller.
3
Who is affected by ZDI-CAN-18862?
Any installations of Oracle WebRTC Session Controller that have not been updated are vulnerable to ZDI-CAN-18862.
4
Can ZDI-CAN-18862 be exploited remotely?
Yes, ZDI-CAN-18862 can be exploited remotely without any authentication required.
5
What are the potential impacts of ZDI-CAN-18862?
The potential impacts of ZDI-CAN-18862 include unauthorized remote access and the ability to execute arbitrary code.