CVE-2020-2733
JD Edwards EnterpriseOne Tools 9.2 - Information Disclosure
Record summary
CVE-2020-2733 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Monitoring and Diagnostics). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
JD Edwards EnterpriseOne ToolsBrowse Oracle Corporation / JD Edwards EnterpriseOne Tools | CVE List | 9.2 | affected |
Proofs of concept
1Repository PoCs
GitHubanmolksachan/CVE-2020-2733Repository PoCby anmolksachanStars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALJD Edwards EnterpriseOne Tools 9.2 - Information DisclosureCVSS 9.8
JD Edwards EnterpriseOne Tools 9.2 is susceptible to information disclosure via the Monitoring and Diagnostics component. An attacker with network access via HTTP can possibly obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
Impact
Successful exploitation of this vulnerability could lead to unauthorized access to sensitive information.
Remediation
Apply the latest security patches or updates provided by the vendor to mitigate this vulnerability.
Source: ProjectDiscovery