CVE-2020-2643
published 2020-01-15CVE-2020-2643: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System). Supported versions that are affected are…
PriorityP431medium6CVSS 3.1
AVNACLPRHUINSUCHILAL
EPSS
1.16%
63.4th percentile
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 6.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle | enterprise_manager_base_platform | — | — |
| oracle_corporation | enterprise_manager_base_platform | — | — |
| oracle_corporation | enterprise_manager_base_platform | — | — |
| oracle_corporation | enterprise_manager_base_platform | — | — |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
nvdv3.06.0MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_oracle6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Job System — CVE-2020-2643
vendor_oracle·2020-01-15·CVSS 6.0
CVE-2020-2643 [MEDIUM] Oracle Oracle Enterprise Manager Risk Matrix: Job System — CVE-2020-2643
Oracle Oracle Enterprise Manager Risk Matrix: Job System vulnerability
CVE: CVE-2020-2643
CVSS: 6.0
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
GHSA
GHSA-pwxf-gxfq-vc37: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System)
ghsa_unreviewed·2022-05-24
CVE-2020-2643 [MEDIUM] GHSA-pwxf-gxfq-vc37: Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System)
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Job System). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data as well as unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 6.0 (Confidentiality, Integrity and Availability imp
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-14326 RESTEasy: Caching routes in RootNode may result in DoS
bugzilla·2020-07-10·CVSS 7.5
CVE-2020-14326 [HIGH] CVE-2020-14326 RESTEasy: Caching routes in RootNode may result in DoS
CVE-2020-14326 RESTEasy: Caching routes in RootNode may result in DoS
The api calls are successfully routed by RestEasy, while this cache grows
unbounded. Due to keys having the same hash code, each subsequent request
gets slower as more cpu time is spent searching and adding the entry. A
simple load generator could exploit this to make the endpoint unresponsive.
The media type itself is cached by MediaTypeHeaderDelegate, which protects
itself by using a fixed size cache (default of 200) that is cleared when
growing beyond the threshold. Since the RootNode cache is unbounded and not
accessible, it is subject to this exploit.
References:
https://issues.redhat.com/browse/RESTEASY-2643
Discussion:
Acknowledgments:
Name: Ben Manes (Vector)
---
Red Hat Enterprise Linux 7 and 8 do not s
Bugzilla
CVE-2020-6506 chromium-browser: Insufficient policy enforcement in WebView
bugzilla·2020-06-16·CVSS 6.5
CVE-2020-6506 [MEDIUM] CVE-2020-6506 chromium-browser: Insufficient policy enforcement in WebView
CVE-2020-6506 chromium-browser: Insufficient policy enforcement in WebView
An insufficient policy enforcement flaw was found in the WebView component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1083819
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1847273]
Affects: fedora-all [bug 1847272]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2643 https://access.redhat.com/errata/RHSA-2020:2643
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.co
Bugzilla
CVE-2020-6507 chromium-browser: Out of bounds write in V8
bugzilla·2020-06-16·CVSS 8.8
CVE-2020-6507 [HIGH] CVE-2020-6507 chromium-browser: Out of bounds write in V8
CVE-2020-6507 chromium-browser: Out of bounds write in V8
An out of bounds write flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1086890
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1847273]
Affects: fedora-all [bug 1847272]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2643 https://access.redhat.com/errata/RHSA-2020:2643
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6507
Bugzilla
CVE-2020-6505 chromium-browser: Use after free in speech
bugzilla·2020-06-16·CVSS 9.6
CVE-2020-6505 [CRITICAL] CVE-2020-6505 chromium-browser: Use after free in speech
CVE-2020-6505 chromium-browser: Use after free in speech
An use after free flaw was found in the speech component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=1081350
External References:
https://chromereleases.googleblog.com/2020/06/stable-channel-update-for-desktop_15.html
Discussion:
Created chromium tracking bugs for this issue:
Affects: epel-all [bug 1847273]
Affects: fedora-all [bug 1847272]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:2643 https://access.redhat.com/errata/RHSA-2020:2643
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-6505
2020-01-15
Published