CVE-2020-2566
published 2020-01-15CVE-2020-2566: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are…
PriorityP423medium4.7CVSS 3.1
AVNACLPRNUIRSCCNILAN
EPSS
1.06%
61.2th percentile
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| imagemagick | imagemagick | >= 0 < 8:6.8.9.9-7ubuntu5.16+esm2 | 8:6.8.9.9-7ubuntu5.16+esm2 |
| linuxfoundation | ceph | >= 0 < 15.2.7-0ubuntu0.20.04.2 | 15.2.7-0ubuntu0.20.04.2 |
| oracle | applications_framework | — | — |
| oracle | applications_framework | 12.2.3 – 12.2.9 | — |
| oracle_corporation | applications_framework | — | — |
| oracle_corporation | applications_framework | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
nvdv3.04.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_oracle4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h2fj-pqv6-fcrr: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload)
ghsa_unreviewed·2022-05-24
CVE-2020-2566 [MEDIUM] GHSA-h2fj-pqv6-fcrr: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload)
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).
OSV
imagemagick vulnerabilities
osv·2022-03-18·CVSS 6.5
CVE-2020-19667 imagemagick vulnerabilities
imagemagick vulnerabilities
It was discovered that ImageMagick incorrectly handled certain values
when processing XPM image data or large images. If a user or automated
system using ImageMagick were tricked into opening a specially crafted
image, an attacker could exploit this to cause a denial of service or
possibly execute code with the privileges of the user invoking the program.
(CVE-2020-19667, CVE-2017-13144)
Suhwan Song discovered that ImageMagick incorrectly handled memory
when processing PNG,PALM,MIFF image data. If a user or automated system
using ImageMagick were tricked into opening a specially crafted image,
an attacker could exploit this to cause a denial of service or possibly
execute code with the privileges of the user invoking the program.
(CVE-2020-25664, CVE-2020-2566
OSV
ceph vulnerabilities
osv·2021-01-28·CVSS 7.5
CVE-2020-10736 ceph vulnerabilities
ceph vulnerabilities
Olle Segerdahl found that ceph-mon and ceph-mgr daemons did not properly
restrict access, resulting in gaining access to unauthorized resources. An
authenticated user could use this vulnerability to modify the configuration and
possibly conduct further attacks. (CVE-2020-10736)
Adam Mohammed found that Ceph Object Gateway was vulnerable to HTTP header
injection via a CORS ExposeHeader tag. An attacker could use this to gain access
or cause a crash. (CVE-2020-10753)
Ilya Dryomov found that Cephx authentication did not verify Ceph clients
correctly and was then vulnerable to replay attacks in Nautilus. An attacker
could use the Ceph cluster network to authenticate via a packet sniffer and
perform actions. This issue is a reintroduction of CVE-2018-1128.
(CVE-2020-2566
Oracle
Oracle Oracle E-Business Suite Risk Matrix: Attachments / File Upload — CVE-2020-2566
vendor_oracle·2020-01-15·CVSS 4.7
CVE-2020-2566 [MEDIUM] Oracle Oracle E-Business Suite Risk Matrix: Attachments / File Upload — CVE-2020-2566
Oracle Oracle E-Business Suite Risk Matrix: Attachments / File Upload vulnerability
CVE: CVE-2020-2566
CVSS: 4.7
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-01-15
Published