PT-2020-3281 · Oracle · Oracle Goldengate

Published

2020-07-15

·

Updated

2020-07-20

·

CVE-2020-14705

CVSS v3.1

9.6

Critical

VectorAV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle GoldenGate versions prior to 19.1.0.0.0
Description The issue is related to insufficient input validation in the Process Management component of Oracle GoldenGate, which can be exploited by a remote attacker to impact the integrity, availability, and confidentiality of information. Successful attacks can result in the takeover of Oracle GoldenGate and may significantly impact additional products.
Recommendations For versions prior to 19.1.0.0.0, update to version 19.1.0.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the physical communication segment attached to the hardware where Oracle GoldenGate executes to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03589
CVE-2020-14705

Affected Products

Oracle Goldengate