cbcvebase.
CVE-2020-2950
published 2020-04-15

CVE-2020-2950: Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions…

PriorityP277critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
71.03%
99.3th percentile
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web General). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected

8 ranges
VendorProductVersion rangeFixed in
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oraclebusiness_intelligence
oracle_corporationoracle_business_intelligence_enterprise_edition
oracle_corporationoracle_business_intelligence_enterprise_edition
oracle_corporationoracle_business_intelligence_enterprise_edition
oracle_corporationoracle_business_intelligence_enterprise_edition

Detection & IOCsextracted from sources · hover to see the quote

port7780
pathBIRemotingServlet
  • CVE-2020-2950 is exploitable via HTTP through BIRemotingServlet on TCP port 7780 with no authentication required; monitor for unexpected deserialization traffic on this port targeting Oracle Business Intelligence.
  • The exploit uses AMF (Action Message Format) packets; inspect AMF3 deserialization traffic to BIRemotingServlet for reconstruction of arbitrary objects via readComplexObject().
  • Exploitation involves a UnicastRef object being reconstructed to trigger the server-side distributed garbage collector, then responding with a gadget chain serialized payload (via ysoserial JRMP listener); detect outbound JRMP connections from the BI server as a post-exploitation indicator.
  • The gadget chains exploit ChainedExtractor.extract() reachable via ExtractorComparator or AbstractExtractor/MultiExtractor; detection rules should look for these class names in deserialized payloads.
  • Oracle Business Intelligence is vulnerable because it is deployed on Oracle WebLogic and has the Coherence library in its code path; any application with Coherence in a deserialization path is at risk.
  • ·Affected Oracle Business Intelligence Enterprise Edition versions are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0, and 12.2.1.4.0; detections should be scoped to these versions.
  • ·The vulnerability is exploitable over HTTP (not just T3/T3S), making network-layer T3 blocking insufficient as a sole mitigation for CVE-2020-2950.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.