CVE-2020-2950
published 2020-04-15CVE-2020-2950: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions…
PriorityP277critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
71.03%
99.3th percentile
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle | business_intelligence | — | — |
| oracle_corporation | oracle_business_intelligence_enterprise_edition | — | — |
| oracle_corporation | oracle_business_intelligence_enterprise_edition | — | — |
| oracle_corporation | oracle_business_intelligence_enterprise_edition | — | — |
| oracle_corporation | oracle_business_intelligence_enterprise_edition | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-2950 is exploitable via HTTP through BIRemotingServlet on TCP port 7780 with no authentication required; monitor for unexpected deserialization traffic on this port targeting Oracle Business Intelligence. ↗
- →The exploit uses AMF (Action Message Format) packets; inspect AMF3 deserialization traffic to BIRemotingServlet for reconstruction of arbitrary objects via readComplexObject(). ↗
- →Exploitation involves a UnicastRef object being reconstructed to trigger the server-side distributed garbage collector, then responding with a gadget chain serialized payload (via ysoserial JRMP listener); detect outbound JRMP connections from the BI server as a post-exploitation indicator. ↗
- →The gadget chains exploit ChainedExtractor.extract() reachable via ExtractorComparator or AbstractExtractor/MultiExtractor; detection rules should look for these class names in deserialized payloads. ↗
- →Oracle Business Intelligence is vulnerable because it is deployed on Oracle WebLogic and has the Coherence library in its code path; any application with Coherence in a deserialization path is at risk. ↗
- ·Affected Oracle Business Intelligence Enterprise Edition versions are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0; detections should be scoped to these versions. ↗
- ·The vulnerability is exploitable over HTTP (not just T3/T3S), making network-layer T3 blocking insufficient as a sole mitigation for CVE-2020-2950. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j639-c36q-pprv: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General)
ghsa_unreviewed·2022-05-24
CVE-2020-2950 [HIGH] GHSA-j639-c36q-pprv: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General)
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Web General — CVE-2020-2950
vendor_oracle·2020-04-15·CVSS 9.8
CVE-2020-2950 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: Analytics Web General — CVE-2020-2950
Oracle Oracle Fusion Middleware Risk Matrix: Analytics Web General vulnerability
CVE: CVE-2020-2950
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Suricata
ET MALWARE URI Struct Observed in Pawn Storm CVE-2015-2950
suricata·2015-07-31·CVSS 6.4
CVE-2015-2950 [MEDIUM] ET MALWARE URI Struct Observed in Pawn Storm CVE-2015-2950
ET MALWARE URI Struct Observed in Pawn Storm CVE-2015-2950
Rule: alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET MALWARE URI Struct Observed in Pawn Storm CVE-2015-2950"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/?p2="; content:"&recr="; distance:0; fast_pattern; content:"&p3="; distance:0; content:"&as="; distance:0; content:"&c="; distance:0; reference:url,blog.trendmicro.com/trendlabs-security-intelligence/an-in-depth-look-at-how-pawn-storms-java-zero-day-was-used/; classtype:trojan-activity; sid:2021560; rev:3; metadata:created_at 2015_07_31, cve CVE_2015_2950, signature_severity Major, updated_at 2020_05_29;)
No public exploits indexed.
Tenable
CVE-2020-2883: Oracle WebLogic Deserialization Vulnerability Exploited in the Wild
blogs_tenable·2020-05-13·CVSS 9.8
[CRITICAL] CVE-2020-2883: Oracle WebLogic Deserialization Vulnerability Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Trendmicro
Oracle WebLogic Vulnerability
blogs_trendmicro·2020-05-11·CVSS 9.8
CVE-2020-2555 [CRITICAL] Oracle WebLogic Vulnerability
# Details on the Oracle WebLogic Vulnerability Being Exploited in the Wild
Learn about one major Oracle WebLogic vulnerability being exploited in the wild.
By: Zero Day Initiative
2020/05/11
Read time: ( words)
Save to Folio
Earlier this year, I blogged about a deserialization vulnerability in the Oracle WebLogic Server. This was patched by Oracle and assigned CVE-2020-2555. However, researcher Quynh Le of VNPT ISC submitted a bug to the ZDI that showed how the patch could be bypassed. This bug, labeled CVE-2020-2883, is now being reported by Oracle as being used in active attacks. In this blog post, we will go through the details of this recently-patched vulnerability.
Patch Bypass
The original patch for CVE-2020-2555 did not address the lower portion of the following gadget chain:
2020-04-15
Published