VendorsUSUoracle_optimization5.16.2
Vulnerabilities

USU Software Oracle Optimization 5.16.2

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2022-29936
USU Oracle Optimization before 5.17 allows authenticated quantum users to achieve remote code execution because of /v2/quantum/save-data-upload-big-file Java deserialization. NOTE: this is not an Oracle Corporation product.
Published 2022-04-29 · Modified
8.8EPSS 0.022
CVE-2022-29934
USU Oracle Optimization before 5.17.5 lacks Polkit authentication, which allows smartcollector users to achieve root access via pkexec. NOTE: this is not an Oracle Corporation product.
Published 2022-04-29 · Modified
7.8EPSS 0.003