PT-2020-4633 · Oracle · Oracle Universal Work Queue

Tuan Anh Nguyen

·

Published

2020-10-21

·

Updated

2020-10-23

·

CVE-2020-14855

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Universal Work Queue version 12.1.3
Description The issue is related to insufficient input validation in the Work Provider Administration component of the Oracle Universal Work Queue application. This can be exploited by a remote attacker to gain unauthorized access to sensitive information, execute arbitrary code, or cause a denial of service.
Recommendations For version 12.1.3, update to a newer version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the Work Provider Administration component to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05184
CVE-2020-14855

Affected Products

Oracle Universal Work Queue