CVE-2020-14615
published 2020-07-15CVE-2020-14615: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.92%
56.3th percentile
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linux | linux_kernel | >= 0 < 4.15.0-76.86 | 4.15.0-76.86 |
| linux | linux_kernel | >= 0 < 4.15.0-91.92 | 4.15.0-91.92 |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.1.0 | — |
| oracle_corporation | financial_services_analytical_applications_infrastructure | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_oracle6.1MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-phhf-gj3g-w9rj: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: In
ghsa_unreviewed·2022-05-24
CVE-2020-14615 [MEDIUM] GHSA-phhf-gj3g-w9rj: Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: In
Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure). Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastru
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
osv·2020-03-25·CVSS 5.5
CVE-2020-2732 linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
Gregory Herrero discovered that the fix for CVE-2019-14615 to address the
Linux kernel not properly clearing data structures on context switches for
certain Intel graphics processors was incomplete. A local attacker could
use this to expose sensitive information. (CVE-2020-8832)
It was discovered that the IPMI message handler implementation in the Li
OSV
linux, linux-aws, linux-oem vulnerabilities
osv·2020-01-28·CVSS 5.5
CVE-2019-14615 linux, linux-aws, linux-oem vulnerabilities
linux, linux-aws, linux-oem vulnerabilities
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition can lead to a use-after-free while
destroying GEM contexts in the i915 driver for the Linux kernel. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2020-7053)
OSV
linux-hwe, linux-aws-hwe vulnerabilities
osv·2020-01-28·CVSS 5.5
CVE-2019-14615 linux-hwe, linux-aws-hwe vulnerabilities
linux-hwe, linux-aws-hwe vulnerabilities
USN-4255-1 fixed vulnerabilities in the Linux kernel for Ubuntu 18.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 18.04 LTS for Ubuntu
16.04 LTS.
It was discovered that the Linux kernel did not properly clear data
structures on context switches for certain Intel graphics processors. A
local attacker could use this to expose sensitive information.
(CVE-2019-14615)
It was discovered that a race condition can lead to a use-after-free while
destroying GEM contexts in the i915 driver for the Linux kernel. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2020-7053)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure — CVE-2020-14615
vendor_oracle·2020-07-15·CVSS 6.1
CVE-2020-14615 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure — CVE-2020-14615
Oracle Oracle Financial Services Applications Risk Matrix: Infrastructure vulnerability
CVE: CVE-2020-14615
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Red Hat
kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
vendor_redhat·2020-03-25·CVSS 5.5
CVE-2020-8832 [MEDIUM] CWE-112 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
An information disclosure flaw was found in the Linux kernel. The original fix for CVE-2019-14615 was deemed to be incomplete. The i915 graphics driver lacks control of flow for data structures which may allow a local, authenticated user to disclose information when using ioctl commands with an attached i915 device. The highest threat from this vulnerability i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]
bugzilla·2020-03-25·CVSS 5.5
CVE-2020-8832 [MEDIUM] CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
bugzilla·2020-03-25·CVSS 5.5
CVE-2020-8832 [MEDIUM] CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
The fix for CVE-2019-14615 to address the Linux kernel not properly clearing data structures on context switches for certain Intel graphics processors was incomplete. A local attacker could use this to expose sensitive information.
https://lists.ubuntu.com/archives/kernel-team/2020-February/107444.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1817048]
---
Mitigation:
Preventing loading of the i915 kernel module will prevent attackers from using this exploit against the system; however, the power management functionality of the card will be disabled and the system may draw additional power. See the kcs “How do I blacklist a kernel module to prevent
2020-07-15
Published