PT-2020-3241 · Oracle · Oracle Berkeley Db

Lionel Debroux

·

Published

2020-07-15

·

Updated

2020-07-20

·

CVE-2020-2981

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Berkeley DB versions prior to 18.1.40
Description The issue exists due to insufficient input validation in the Data Store component of Oracle Berkeley DB. Exploitation of this issue can allow an attacker to gain full control over the system. The vulnerability is difficult to exploit and requires an unauthenticated attacker with logon to the infrastructure where Data Store executes. Successful attacks also require human interaction from a person other than the attacker, which can result in the takeover of Data Store.
Recommendations For versions prior to 18.1.40, update to version 18.1.40 or later to resolve the issue. As a temporary workaround, consider restricting access to the Data Store component to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-34928
AZL-6631
BDU:2020-03545
CVE-2020-2981

Affected Products

Oracle Berkeley Db