CVE-2020-14855
published 2020-10-21CVE-2020-14855: Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). The supported version that is…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
2.15%
80.0th percentile
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | universal_work_queue | — | — |
| oracle_corporation | universal_work_queue | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-14855 targets Oracle Universal Work Queue (Work Provider Administration component) in Oracle E-Business Suite version 12.1.3 via unauthenticated HTTP network access — monitor for unexpected or unauthenticated HTTP requests to Work Provider Administration endpoints in EBS 12.1.3 ↗
- →The vulnerability is remotely exploitable with no authentication required (PR:N/UI:N) over HTTP, resulting in full takeover (C:H/I:H/A:H) — alert on anomalous unauthenticated access patterns to Oracle EBS Work Queue administration interfaces ↗
- ·Only Oracle E-Business Suite version 12.1.3 is listed as affected; other EBS versions are not confirmed vulnerable per the advisory ↗
- ·The attack vector is network (HTTP) with no authentication or user interaction required, meaning no network segmentation or authentication controls are in place by default to prevent exploitation ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w32j-frr3-h6w4: Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration)
ghsa_unreviewed·2022-05-24
CVE-2020-14855 [CRITICAL] GHSA-w32j-frr3-h6w4: Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration)
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Oracle
Oracle Oracle E-Business Suite Risk Matrix: Work Provider Administration — CVE-2020-14855
vendor_oracle·2020-10-15·CVSS 9.8
CVE-2020-14855 [CRITICAL] Oracle Oracle E-Business Suite Risk Matrix: Work Provider Administration — CVE-2020-14855
Oracle Oracle E-Business Suite Risk Matrix: Work Provider Administration vulnerability
CVE: CVE-2020-14855
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
No detection rules found.
No public exploits indexed.
2020-10-21
Published