PT-2020-1495 · Oracle · Enterprise Manager For Fusion Middleware
Alexander Kornbrust
·
Published
2020-01-14
·
Updated
2022-04-29
·
CVE-2020-2614
CVSS v2.0
8.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Enterprise Manager for Fusion Middleware versions 13.2.0.0 through 13.3.0.0
Description
The issue is related to insufficient access control in the APM Mesh component of the Enterprise Manager for Fusion Middleware product. It allows a remote attacker to gain access to modify, add, or delete data, obtain unauthorized access to protected information, or cause a denial of service using the HTTP protocol. Successful attacks can result in unauthorized access to critical data, complete access to all accessible data, unauthorized update, insert, or delete access to some data, and the ability to cause a partial denial of service.
Recommendations
For versions 13.2.0.0 and 13.3.0.0, consider restricting access to the APM Mesh component until a patch is available.
As a temporary workaround, limit network access via HTTP to the Enterprise Manager for Fusion Middleware to minimize the risk of exploitation.
Avoid using the HTTP protocol for sensitive operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Enterprise Manager For Fusion Middleware