VYPR
Vendor

USU

Products
1
CVEs
4
Across products
4
Status
Private

Products

1

Recent CVEs

4
  • CVE-2022-29937HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.01

    USU Oracle Optimization before 5.17.5 allows authenticated DataCollection users to achieve agent root access because some common OS commands are blocked but (for example) an OS command for base64 decoding is not blocked. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29936HigApr 29, 2022
    risk 0.57cvss 8.8epss 0.02

    USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29934HigApr 29, 2022
    risk 0.51cvss 7.8epss 0.00

    USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.

  • CVE-2022-29935HigApr 29, 2022
    risk 0.49cvss 7.5epss 0.01

    USU Oracle Optimization before 5.17.5 allows attackers to discover the quantum credentials via an agent-installer download. NOTE: this is not an Oracle Corporation product.