CVE-2020-0227
published 2020-07-17CVE-2020-0227: In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.4th percentile
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| platform | cts | >= 10:0 < 10:2020-07-01 | 10:2020-07-01 |
| platform | cts | >= 8.0:0 < 8.0:2020-07-01 | 8.0:2020-07-01 |
| platform | cts | >= 8.1:0 < 8.1:2020-07-01 | 8.1:2020-07-01 |
| platform | cts | >= 9:0 < 9:2020-07-01 | 9:2020-07-01 |
| platform | frameworks_base | >= 10:0 < 10:2020-07-01 | 10:2020-07-01 |
| platform | frameworks_base | >= 8.0:0 < 8.0:2020-07-01 | 8.0:2020-07-01 |
| platform | frameworks_base | >= 8.1:0 < 8.1:2020-07-01 | 8.1:2020-07-01 |
| platform | frameworks_base | >= 9:0 < 9:2020-07-01 | 9:2020-07-01 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_oracle7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w2jf-83j8-x6v6: In onCommand of CompanionDeviceManagerService
ghsa_unreviewed·2022-05-24
CVE-2020-0227 [HIGH] CWE-276 GHSA-w2jf-83j8-x6v6: In onCommand of CompanionDeviceManagerService
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618
OSV
CVE-2020-0227: In onCommand of CompanionDeviceManagerService
osv·2020-07-01
CVE-2020-0227 CVE-2020-0227: In onCommand of CompanionDeviceManagerService
In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Adapters (Apache Axis) — CVE-2019-0227
vendor_oracle·2020-07-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Adapters (Apache Axis) — CVE-2019-0227
Oracle Oracle Communications Applications Risk Matrix: Adapters (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujul2020 (JUL 2020)
Android
CVE-2020-0227: Android Security Bulletin 2020-07-01
CVE: CVE-2020-0227
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
vendor_android·2020-07-01·CVSS 7.8
CVE-2020-0227 [HIGH] CVE-2020-0227: Android Security Bulletin 2020-07-01
CVE: CVE-2020-0227
Severity: HIGH
Type: EoP
Affected AOSP versions: 8
Android Security Bulletin 2020-07-01
CVE: CVE-2020-0227
Severity: HIGH
Type: EoP
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-129476618
[2]
[3]
[4]
[5]
[6]
Oracle
Oracle Oracle Communications Applications Risk Matrix: Web Service (Apache Axis) — CVE-2019-0227
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Web Service (Apache Axis) — CVE-2019-0227
Oracle Oracle Communications Applications Risk Matrix: Web Service (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Axis) — CVE-2019-0227
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2019-0227 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Axis) — CVE-2019-0227
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Axis) vulnerability
CVE: CVE-2019-0227
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Adjacent
Network
Advisory: cpujan2020 (JAN 2020)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-07-17
Published