Record summary

CVE-2020-2733 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 30, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List9.2affected

Proofs of concept

1

Repository PoCs

GitHubanmolksachan/CVE-2020-2733Repository PoCby anmolksachanStars: 1Not analyzed2 files

6.6 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALJD Edwards EnterpriseOne Tools 9.2 - Information DisclosureCVSS 9.8

JD Edwards EnterpriseOne Tools 9.2 is susceptible to information disclosure via the Monitoring and Diagnostics component. An attacker with network access via HTTP can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.

Impact

Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information.

Remediation

Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.

AuthorsDhiyaneshDk, pussycat0x
Template tagscve2020cveoracleweblogicdisclosureexposurevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*
Shodan: port:8999 product:"Oracle WebLogic Server"
Shodan: port:8999 product:"oracle weblogic server"

Source: ProjectDiscovery

References

2